Files
craftvia/seed/isms-vorlagenpaket-v2-en/mapping.json
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

5352 lines
168 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
{
"meta": {
"paket": "ISMS-Vorlagenpaket v2",
"standard": "VDA ISA 2027 (Information Security)",
"hinweis": "Anforderungen 1:1 aus ISA; Umsetzung gebuendelt je Control. is_isa=false = kundenspezifische Ergaenzung (z.B. KI).",
"isa_quelldubletten": [
{
"control": "1.6.3",
"ebene": "high",
"doppelte_quellzeilen": 3,
"abgedeckt_durch": [
"1.6.3-H1",
"1.6.3-H2",
"1.6.3-H5"
],
"hinweis": "ISA wiederholt Krisenszenario-/Ressourcen-/Test-Zeilen mit/ohne Zusatz \"The following aspects are considered\"."
},
{
"control": "5.2.9",
"ebene": "high",
"doppelte_quellzeilen": 1,
"abgedeckt_durch": [
"5.2.9-H1"
],
"hinweis": "ISA-Zeile \"Backup and recovery concepts exist\" ist redundant zum Must-Konzept und zu H1."
}
],
"coverage": "316 eindeutige ISA-Zeilen; 4 Quelldubletten konsolidiert -> 312 eindeutige Anforderungen (100% inhaltliche Abdeckung). Plus 4 kundenspezifische KI-Anforderungen.",
"version": "2.1"
},
"anforderungen": [
{
"id": "1.1.1-M1",
"policy": "L00",
"control": "1.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.1.1-M1",
"impl_anchor": "REQ 1.1.1-M1",
"condition": null,
"requirement": "The information security requirements are defined, documented and aligned with the objectives of the organisation.",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.1.1-M2",
"policy": "L00",
"control": "1.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.1.1-M2",
"impl_anchor": "REQ 1.1.1-M2",
"condition": null,
"requirement": "A policy exists and is approved by the organisation's management.",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.1.1-M3",
"policy": "L00",
"control": "1.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.1.1-M3",
"impl_anchor": "REQ 1.1.1-M3",
"condition": null,
"requirement": "The policy states the objectives and the importance of information security within the organisation.",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.1.1-M4",
"policy": "L00",
"control": "1.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.1.1-M4",
"impl_anchor": "REQ 1.1.1-M4",
"condition": null,
"requirement": "The policies are made available to employees in a suitable form (e.g. intranet).",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.1.1-M5",
"policy": "L00",
"control": "1.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.1.1-M5",
"impl_anchor": "REQ 1.1.1-M5",
"condition": null,
"requirement": "Employees and external business partners are informed about changes relevant to them.",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.1.1-S1",
"policy": "L00",
"control": "1.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.1.1-S1",
"impl_anchor": "REQ 1.1.1-S1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The information security requirements are based on the organisation's strategy; laws and contracts are taken into account in the policy.",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.1.1-S2",
"policy": "L00",
"control": "1.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.1.1-S2",
"impl_anchor": "REQ 1.1.1-S2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The policy states the consequences of non-compliance.",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.1.1-S3",
"policy": "L00",
"control": "1.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.1.1-S3",
"impl_anchor": "REQ 1.1.1-S3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Further relevant security policies are established.",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.1.1-S4",
"policy": "L00",
"control": "1.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.1.1-S4",
"impl_anchor": "REQ 1.1.1-S4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Regular review and, where necessary, revision of the policies are established.",
"link": "{{LINK:L00#1.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.1-M1",
"policy": "R01",
"control": "1.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.1-M1",
"impl_anchor": "IMPL 1.2.1",
"condition": null,
"requirement": "The scope of the ISMS (the organisation governed by the ISMS) is defined.",
"link": "{{LINK:R01#1.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.1-M2",
"policy": "R01",
"control": "1.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.1-M2",
"impl_anchor": "IMPL 1.2.1",
"condition": null,
"requirement": "The organisation's requirements for the ISMS are determined.",
"link": "{{LINK:R01#1.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.1-M3",
"policy": "R01",
"control": "1.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.1-M3",
"impl_anchor": "IMPL 1.2.1",
"condition": null,
"requirement": "The organisation's management has commissioned and approved the ISMS.",
"link": "{{LINK:R01#1.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.1-M4",
"policy": "R01",
"control": "1.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.1-M4",
"impl_anchor": "IMPL 1.2.1",
"condition": null,
"requirement": "The ISMS provides management with suitable means for monitoring and steering (e.g. management review).",
"link": "{{LINK:R01#1.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.1-M5",
"policy": "R01",
"control": "1.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.1-M5",
"impl_anchor": "IMPL 1.2.1",
"condition": null,
"requirement": "The applicable controls are determined (e.g. ISO 27001 statement of applicability or a completed ISA catalogue).",
"link": "{{LINK:R01#1.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.1-M6",
"policy": "R01",
"control": "1.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.1-M6",
"impl_anchor": "IMPL 1.2.1",
"condition": null,
"requirement": "The effectiveness of the ISMS is reviewed regularly by management.",
"link": "{{LINK:R01#1.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.2-M1",
"policy": "R01",
"control": "1.2.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.2-M1",
"impl_anchor": "IMPL 1.2.2",
"condition": null,
"requirement": "Responsibilities for information security are defined, documented and assigned.",
"link": "{{LINK:R01#1.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.2-M2",
"policy": "R01",
"control": "1.2.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.2-M2",
"impl_anchor": "IMPL 1.2.2",
"condition": null,
"requirement": "The responsible employees are defined, qualified and enabled for their task.",
"link": "{{LINK:R01#1.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.2-M3",
"policy": "R01",
"control": "1.2.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.2-M3",
"impl_anchor": "IMPL 1.2.2",
"condition": null,
"requirement": "The necessary resources are available.",
"link": "{{LINK:R01#1.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.2-M4",
"policy": "R01",
"control": "1.2.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.2-M4",
"impl_anchor": "IMPL 1.2.2",
"condition": null,
"requirement": "The points of contact are known within the organisation and to relevant business partners.",
"link": "{{LINK:R01#1.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.2-S1",
"policy": "R01",
"control": "1.2.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.2.2-S1",
"impl_anchor": "IMPL 1.2.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "An appropriate information security structure within the organisation is defined and documented.",
"link": "{{LINK:R01#1.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.2-S2",
"policy": "R01",
"control": "1.2.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.2.2-S2",
"impl_anchor": "IMPL 1.2.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Security-relevant roles that are not part of the ISMS but are relevant to information security are taken into account.",
"link": "{{LINK:R01#1.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.2-H1",
"policy": "R01",
"control": "1.2.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.2.2-H1",
"impl_anchor": "IMPL 1.2.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "An appropriate organisational separation of responsibilities is established to avoid conflicts of interest (segregation of duties). (C, I, A)",
"link": "{{LINK:R01#1.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.2.3-M1",
"policy": "R01",
"control": "1.2.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.2.3-M1",
"impl_anchor": "IMPL 1.2.3",
"condition": null,
"requirement": "Projects are classified taking information security requirements into account.",
"link": "{{LINK:R01#1.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-19"
]
},
{
"id": "1.2.3-S1",
"policy": "R01",
"control": "1.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.2.3-S1",
"impl_anchor": "IMPL 1.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Procedures and criteria for classifying projects are documented.",
"link": "{{LINK:R01#1.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-19"
]
},
{
"id": "1.2.3-S2",
"policy": "R01",
"control": "1.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.2.3-S2",
"impl_anchor": "IMPL 1.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A risk assessment following the defined procedure is carried out in an early project phase and repeated upon project changes.",
"link": "{{LINK:R01#1.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-19"
]
},
{
"id": "1.2.3-S3",
"policy": "R01",
"control": "1.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.2.3-S3",
"impl_anchor": "IMPL 1.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Measures are derived for identified information security risks and taken into account in the project.",
"link": "{{LINK:R01#1.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-19"
]
},
{
"id": "1.2.3-H1",
"policy": "R01",
"control": "1.2.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.2.3-H1",
"impl_anchor": "IMPL 1.2.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The derived measures are reviewed regularly during the project and reassessed when the assessment criteria change. (C, I, A)",
"link": "{{LINK:R01#1.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-19"
]
},
{
"id": "1.3.1-M1",
"policy": "R02",
"control": "1.3.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.1-M1",
"impl_anchor": "IMPL 1.3.1",
"condition": null,
"requirement": "The organisation's information assets and other security-relevant assets are identified and recorded.",
"link": "{{LINK:R02#1.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-08"
]
},
{
"id": "1.3.1-M2",
"policy": "R02",
"control": "1.3.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.1-M2",
"impl_anchor": "IMPL 1.3.1",
"condition": null,
"requirement": "The supporting assets that process the information assets are identified and recorded.",
"link": "{{LINK:R02#1.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-08"
]
},
{
"id": "1.3.1-S1",
"policy": "R02",
"control": "1.3.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.1-S1",
"impl_anchor": "IMPL 1.3.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A catalogue of the relevant information assets exists; the relevant aspects are taken into account.",
"link": "{{LINK:R02#1.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-08"
]
},
{
"id": "1.3.2-M1",
"policy": "R02",
"control": "1.3.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.2-M1",
"impl_anchor": "IMPL 1.3.2",
"condition": null,
"requirement": "A consistent scheme for classifying information assets with regard to the protection goal of confidentiality is in place.",
"link": "{{LINK:R02#1.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-08"
]
},
{
"id": "1.3.2-M2",
"policy": "R02",
"control": "1.3.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.2-M2",
"impl_anchor": "IMPL 1.3.2",
"condition": null,
"requirement": "The identified information assets are assessed according to the defined criteria and assigned to the classification scheme.",
"link": "{{LINK:R02#1.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-08"
]
},
{
"id": "1.3.2-M3",
"policy": "R02",
"control": "1.3.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.2-M3",
"impl_anchor": "IMPL 1.3.2",
"condition": null,
"requirement": "Requirements for handling supporting assets (e.g. labelling, use, transport, storage, return, deletion/destruction) depending on the classification are in place and implemented.",
"link": "{{LINK:R02#1.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.2-S1",
"policy": "R02",
"control": "1.3.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.2-S1",
"impl_anchor": "IMPL 1.3.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The protection goals of integrity and availability are taken into account.",
"link": "{{LINK:R02#1.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-08"
]
},
{
"id": "1.3.3-M1",
"policy": "R02",
"control": "1.3.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.3-M1",
"impl_anchor": "IMPL 1.3.3",
"condition": null,
"requirement": "External IT services are not used without an explicit assessment and implementation of the information security requirements; the relevant aspects are taken into account.",
"link": "{{LINK:R02#1.3.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.3-M2",
"policy": "R02",
"control": "1.3.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.3-M2",
"impl_anchor": "IMPL 1.3.3",
"condition": null,
"requirement": "The external IT services are aligned with the protection need of the information assets processed.",
"link": "{{LINK:R02#1.3.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.3-S1",
"policy": "R02",
"control": "1.3.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.3-S1",
"impl_anchor": "IMPL 1.3.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Requirements for procurement, commissioning and approval in connection with the use of external IT services are determined and met.",
"link": "{{LINK:R02#1.3.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.3-S2",
"policy": "R02",
"control": "1.3.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.3-S2",
"impl_anchor": "IMPL 1.3.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A procedure for approval taking the protection need into account is established.",
"link": "{{LINK:R02#1.3.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.3-S3",
"policy": "R02",
"control": "1.3.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.3-S3",
"impl_anchor": "IMPL 1.3.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "External IT services and their approval are documented.",
"link": "{{LINK:R02#1.3.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.3-S4",
"policy": "R02",
"control": "1.3.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.3-S4",
"impl_anchor": "IMPL 1.3.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "It is regularly verified that only approved external IT services are used.",
"link": "{{LINK:R02#1.3.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.4-M1",
"policy": "R02",
"control": "1.3.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.4-M1",
"impl_anchor": "IMPL 1.3.4",
"condition": null,
"requirement": "Software is approved before installation or use; the relevant aspects are taken into account.",
"link": "{{LINK:R02#1.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.4-M2",
"policy": "R02",
"control": "1.3.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.3.4-M2",
"impl_anchor": "IMPL 1.3.4",
"condition": null,
"requirement": "The software approval also applies to special software such as maintenance tools.",
"link": "{{LINK:R02#1.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.4-S1",
"policy": "R02",
"control": "1.3.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.4-S1",
"impl_anchor": "IMPL 1.3.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The types of software to be managed (firmware, operating systems, applications, libraries, device drivers) are determined.",
"link": "{{LINK:R02#1.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.4-S2",
"policy": "R02",
"control": "1.3.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.4-S2",
"impl_anchor": "IMPL 1.3.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Repositories of the managed software exist.",
"link": "{{LINK:R02#1.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.4-S3",
"policy": "R02",
"control": "1.3.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.4-S3",
"impl_anchor": "IMPL 1.3.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The software repositories are protected against unauthorised manipulation.",
"link": "{{LINK:R02#1.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.4-S4",
"policy": "R02",
"control": "1.3.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.4-S4",
"impl_anchor": "IMPL 1.3.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The approval of software is reviewed regularly.",
"link": "{{LINK:R02#1.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.4-S5",
"policy": "R02",
"control": "1.3.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.3.4-S5",
"impl_anchor": "IMPL 1.3.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Software versions and patch levels are known.",
"link": "{{LINK:R02#1.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.3.4-V1",
"policy": "R02",
"control": "1.3.4",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 1.3.4-V1",
"impl_anchor": "IMPL 1.3.4-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Additional requirements for software use (e.g. the need to control/monitor use) are determined where present. (C, I, A)",
"link": "{{LINK:R02#1.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.4.1-M1",
"policy": "R03",
"control": "1.4.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.4.1-M1",
"impl_anchor": "IMPL 1.4.1",
"condition": null,
"requirement": "Risk assessments are carried out regularly and on an ad-hoc basis.",
"link": "{{LINK:R03#1.4.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-09"
]
},
{
"id": "1.4.1-M2",
"policy": "R03",
"control": "1.4.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.4.1-M2",
"impl_anchor": "IMPL 1.4.1",
"condition": null,
"requirement": "Information security risks are assessed appropriately (e.g. likelihood of occurrence and potential extent of damage).",
"link": "{{LINK:R03#1.4.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-09"
]
},
{
"id": "1.4.1-M3",
"policy": "R03",
"control": "1.4.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.4.1-M3",
"impl_anchor": "IMPL 1.4.1",
"condition": null,
"requirement": "Information security risks are documented.",
"link": "{{LINK:R03#1.4.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-09"
]
},
{
"id": "1.4.1-M4",
"policy": "R03",
"control": "1.4.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.4.1-M4",
"impl_anchor": "IMPL 1.4.1",
"condition": null,
"requirement": "A responsible person (risk owner) is assigned to each information security risk and is responsible for its assessment and treatment.",
"link": "{{LINK:R03#1.4.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.4.1-S1",
"policy": "R03",
"control": "1.4.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.4.1-S1",
"impl_anchor": "IMPL 1.4.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A procedure for the identification, assessment and treatment of security risks is in place.",
"link": "{{LINK:R03#1.4.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-09"
]
},
{
"id": "1.4.1-S2",
"policy": "R03",
"control": "1.4.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.4.1-S2",
"impl_anchor": "IMPL 1.4.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Criteria for the assessment and treatment of security risks exist.",
"link": "{{LINK:R03#1.4.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.4.1-S3",
"policy": "R03",
"control": "1.4.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.4.1-S3",
"impl_anchor": "IMPL 1.4.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Risk treatment measures and their responsible persons are defined and documented; a measures plan or implementation overview is tracked.",
"link": "{{LINK:R03#1.4.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.4.1-S4",
"policy": "R03",
"control": "1.4.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.4.1-S4",
"impl_anchor": "IMPL 1.4.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Upon changes in the environment (e.g. organisational structure, location, regulations), a reassessment is carried out promptly.",
"link": "{{LINK:R03#1.4.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.5.1-M1",
"policy": "R03",
"control": "1.5.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.5.1-M1",
"impl_anchor": "IMPL 1.5.1",
"condition": null,
"requirement": "Compliance with the policies is reviewed organisation-wide.",
"link": "{{LINK:R03#1.5.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.5.1-M2",
"policy": "R03",
"control": "1.5.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.5.1-M2",
"impl_anchor": "IMPL 1.5.1",
"condition": null,
"requirement": "Information security policies and procedures are reviewed regularly.",
"link": "{{LINK:R03#1.5.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.5.1-M3",
"policy": "R03",
"control": "1.5.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.5.1-M3",
"impl_anchor": "IMPL 1.5.1",
"condition": null,
"requirement": "Measures to correct possible deviations are initiated and tracked.",
"link": "{{LINK:R03#1.5.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.5.1-M4",
"policy": "R03",
"control": "1.5.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.5.1-M4",
"impl_anchor": "IMPL 1.5.1",
"condition": null,
"requirement": "Compliance with information security requirements (e.g. technical specifications) is reviewed regularly.",
"link": "{{LINK:R03#1.5.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.5.1-M5",
"policy": "R03",
"control": "1.5.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.5.1-M5",
"impl_anchor": "IMPL 1.5.1",
"condition": null,
"requirement": "The results of the reviews carried out are recorded and retained.",
"link": "{{LINK:R03#1.5.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.5.1-S1",
"policy": "R03",
"control": "1.5.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.5.1-S1",
"impl_anchor": "IMPL 1.5.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A plan for the content and framework conditions (schedule, scope, controls) of the reviews to be carried out is in place.",
"link": "{{LINK:R03#1.5.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.5.2-M1",
"policy": "R03",
"control": "1.5.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.5.2-M1",
"impl_anchor": "IMPL 1.5.2",
"condition": null,
"requirement": "Information security reviews are carried out by an independent and competent body regularly and after fundamental changes.",
"link": "{{LINK:R03#1.5.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.5.2-M2",
"policy": "R03",
"control": "1.5.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.5.2-M2",
"impl_anchor": "IMPL 1.5.2",
"condition": null,
"requirement": "Measures to correct possible deviations are initiated and tracked.",
"link": "{{LINK:R03#1.5.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.5.2-S1",
"policy": "R03",
"control": "1.5.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.5.2-S1",
"impl_anchor": "IMPL 1.5.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The results of the reviews carried out are documented and reported to the organisation's management.",
"link": "{{LINK:R03#1.5.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-15"
]
},
{
"id": "1.6.1-M1",
"policy": "R04",
"control": "1.6.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.1-M1",
"impl_anchor": "IMPL 1.6.1",
"condition": null,
"requirement": "A definition of a reportable security event or observation exists and is known to employees and relevant stakeholders.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-01"
]
},
{
"id": "1.6.1-M2",
"policy": "R04",
"control": "1.6.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.1-M2",
"impl_anchor": "IMPL 1.6.1",
"condition": null,
"requirement": "Appropriate, risk-oriented mechanisms for reporting security events are defined, implemented and known to all relevant reporters.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-01"
]
},
{
"id": "1.6.1-M3",
"policy": "R04",
"control": "1.6.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.1-M3",
"impl_anchor": "IMPL 1.6.1",
"condition": null,
"requirement": "Appropriate channels for communicating with reporters exist.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.1-S1",
"policy": "R04",
"control": "1.6.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.1-S1",
"impl_anchor": "IMPL 1.6.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A common point of contact for event reporting exists.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.1-S2",
"policy": "R04",
"control": "1.6.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.1-S2",
"impl_anchor": "IMPL 1.6.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Different reporting channels depending on the perceived severity (real-time for serious events/emergencies as well as asynchronous mechanisms such as tickets or email) are available.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.1-S3",
"policy": "R04",
"control": "1.6.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.1-S3",
"impl_anchor": "IMPL 1.6.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Employees are obliged and trained to report relevant events.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.1-S4",
"policy": "R04",
"control": "1.6.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.1-S4",
"impl_anchor": "IMPL 1.6.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Security events can also be reported by external parties; the relevant aspects are taken into account.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.1-S5",
"policy": "R04",
"control": "1.6.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.1-S5",
"impl_anchor": "IMPL 1.6.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The mechanism and the information on how incidents are reported are accessible to all relevant reporters.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.1-S6",
"policy": "R04",
"control": "1.6.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.1-S6",
"impl_anchor": "IMPL 1.6.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A feedback procedure to the reporters is established.",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.1-V1",
"policy": "R04",
"control": "1.6.1",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.1-V1",
"impl_anchor": "IMPL 1.6.1-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Tests and exercises of event and observation reporting are carried out regularly. (C, I, A)",
"link": "{{LINK:R04#1.6.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.2-M1",
"policy": "R04",
"control": "1.6.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.2-M1",
"impl_anchor": "IMPL 1.6.2",
"condition": null,
"requirement": "Reported events are processed without undue delay.",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-01"
]
},
{
"id": "1.6.2-M2",
"policy": "R04",
"control": "1.6.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.2-M2",
"impl_anchor": "IMPL 1.6.2",
"condition": null,
"requirement": "An appropriate response to reported security events is ensured.",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-01"
]
},
{
"id": "1.6.2-M3",
"policy": "R04",
"control": "1.6.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.2-M3",
"impl_anchor": "IMPL 1.6.2",
"condition": null,
"requirement": "Lessons learned feed into continual improvement.",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.2-S1",
"policy": "R04",
"control": "1.6.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.2-S1",
"impl_anchor": "IMPL 1.6.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "During processing, reported events are categorised (e.g. personnel, physical, cyber), qualified (e.g. not security-relevant, observation, improvement suggestion, vulnerability, incident) and prioritised (e.g. low, medium, high, critical).",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-01"
]
},
{
"id": "1.6.2-S2",
"policy": "R04",
"control": "1.6.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.2-S2",
"impl_anchor": "IMPL 1.6.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Responsibilities for handling events per category are defined and assigned.",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-01"
]
},
{
"id": "1.6.2-S3",
"policy": "R04",
"control": "1.6.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.2-S3",
"impl_anchor": "IMPL 1.6.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A strategy for reporting potentially criminally relevant aspects to the competent authorities, where necessary, exists. (C, I, A)",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.2-H1",
"policy": "R04",
"control": "1.6.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.2-H1",
"impl_anchor": "IMPL 1.6.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Maximum response times per class, category and severity are defined. (C, I, A)",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.2-H2",
"policy": "R04",
"control": "1.6.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.2-H2",
"impl_anchor": "IMPL 1.6.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Events not processed in line with their priority are escalated; the relevant aspects are taken into account. (C, I, A)",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.2-H3",
"policy": "R04",
"control": "1.6.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.2-H3",
"impl_anchor": "IMPL 1.6.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Legal, regulatory and contractual reporting obligations and the associated contact information are known. (C, I, A)",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.2-H4",
"policy": "R04",
"control": "1.6.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.2-H4",
"impl_anchor": "IMPL 1.6.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "A communication strategy for security-relevant events exists; the relevant aspects are taken into account. (C, I, A)",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.2-H5",
"policy": "R04",
"control": "1.6.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.2-H5",
"impl_anchor": "IMPL 1.6.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Procedures for responding to security incidents at suppliers are established; the relevant aspects are taken into account. (C, I, A)",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.2-V1",
"policy": "R04",
"control": "1.6.2",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.2-V1",
"impl_anchor": "IMPL 1.6.2-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "The handling of events of different categories and priorities is tested regularly; the relevant aspects are taken into account. (A)",
"link": "{{LINK:R04#1.6.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-M1",
"policy": "R04",
"control": "1.6.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.3-M1",
"impl_anchor": "IMPL 1.6.3",
"condition": null,
"requirement": "An appropriate plan for responding to and managing crisis situations exists and the necessary resources are available.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-02"
]
},
{
"id": "1.6.3-M2",
"policy": "R04",
"control": "1.6.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.3-M2",
"impl_anchor": "IMPL 1.6.3",
"condition": null,
"requirement": "Responsibilities and authorities for crisis management are defined, documented and assigned.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-M3",
"policy": "R04",
"control": "1.6.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 1.6.3-M3",
"impl_anchor": "IMPL 1.6.3",
"condition": null,
"requirement": "The responsible employees are defined and qualified for their task.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-S1",
"policy": "R04",
"control": "1.6.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.3-S1",
"impl_anchor": "IMPL 1.6.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Methods for detecting crisis situations are established; general indicators and specific foreseeable crises are identified.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-02"
]
},
{
"id": "1.6.3-S2",
"policy": "R04",
"control": "1.6.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.3-S2",
"impl_anchor": "IMPL 1.6.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A procedure for triggering and/or escalating crisis management is in place.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-S3",
"policy": "R04",
"control": "1.6.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.3-S3",
"impl_anchor": "IMPL 1.6.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Strategic objectives and their priority in crisis situations are defined and known to relevant personnel.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-S4",
"policy": "R04",
"control": "1.6.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.3-S4",
"impl_anchor": "IMPL 1.6.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A crisis team is defined and approved.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-S5",
"policy": "R04",
"control": "1.6.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.3-S5",
"impl_anchor": "IMPL 1.6.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Crisis policies and procedures are defined and approved.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-S6",
"policy": "R04",
"control": "1.6.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 1.6.3-S6",
"impl_anchor": "IMPL 1.6.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The crisis planning is reviewed and updated regularly.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-H1",
"policy": "R04",
"control": "1.6.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.3-H1",
"impl_anchor": "IMPL 1.6.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Relevant different potential crisis scenarios are identified.",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-H2",
"policy": "R04",
"control": "1.6.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.3-H2",
"impl_anchor": "IMPL 1.6.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The resources and information necessary for crisis management (e.g. communication infrastructure, availability of contact and risk information) are identified; appropriate measures to ensure availability or fallback planning are in place. (A)",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-H3",
"policy": "R04",
"control": "1.6.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.3-H3",
"impl_anchor": "IMPL 1.6.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "A communication strategy for crisis situations exists. (A)",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-H4",
"policy": "R04",
"control": "1.6.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.3-H4",
"impl_anchor": "IMPL 1.6.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The efficiency, feasibility and appropriateness of the crisis planning are assessed regularly. (A)",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-H5",
"policy": "R04",
"control": "1.6.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.3-H5",
"impl_anchor": "IMPL 1.6.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Sample-based tests of the crisis planning are carried out (e.g. simulation, tabletop exercises with key personnel). (A)",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "1.6.3-V1",
"policy": "R04",
"control": "1.6.3",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 1.6.3-V1",
"impl_anchor": "IMPL 1.6.3-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Crisis exercises and simulations involving all relevant persons, including decision-makers, are carried out regularly. (A)",
"link": "{{LINK:R04#1.6.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.1-M1",
"policy": "R05",
"control": "2.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 2.1.1-M1",
"impl_anchor": "IMPL 2.1.1",
"condition": null,
"requirement": "Sensitive work areas and activities are determined.",
"link": "{{LINK:R05#2.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.1-M2",
"policy": "R05",
"control": "2.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 2.1.1-M2",
"impl_anchor": "IMPL 2.1.1",
"condition": null,
"requirement": "The requirements for employees with regard to their job profiles are determined and met.",
"link": "{{LINK:R05#2.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.1-M3",
"policy": "R05",
"control": "2.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 2.1.1-M3",
"impl_anchor": "IMPL 2.1.1",
"condition": null,
"requirement": "The identity of potential employees is verified (e.g. checking of identity documents).",
"link": "{{LINK:R05#2.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.1-S1",
"policy": "R05",
"control": "2.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.1-S1",
"impl_anchor": "IMPL 2.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The personal suitability of potential employees is checked using simple methods (e.g. job interview).",
"link": "{{LINK:R05#2.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.1-S2",
"policy": "R05",
"control": "2.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.1-S2",
"impl_anchor": "IMPL 2.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "An extended suitability check depending on the work area and the activity is carried out (e.g. assessment centre, checking of references, certificates and criminal record certificates).",
"link": "{{LINK:R05#2.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.2-M1",
"policy": "R05",
"control": "2.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 2.1.2-M1",
"impl_anchor": "IMPL 2.1.2",
"condition": null,
"requirement": "A confidentiality obligation is in force.",
"link": "{{LINK:R05#2.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.2-M2",
"policy": "R05",
"control": "2.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 2.1.2-M2",
"impl_anchor": "IMPL 2.1.2",
"condition": null,
"requirement": "An obligation to comply with the information security policies is in force.",
"link": "{{LINK:R05#2.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.2-S1",
"policy": "R05",
"control": "2.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.2-S1",
"impl_anchor": "IMPL 2.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A confidentiality obligation going beyond the employment contract is in force.",
"link": "{{LINK:R05#2.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.2-S2",
"policy": "R05",
"control": "2.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.2-S2",
"impl_anchor": "IMPL 2.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Information security aspects are taken into account in the employees' employment contracts.",
"link": "{{LINK:R05#2.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.2-S3",
"policy": "R05",
"control": "2.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.2-S3",
"impl_anchor": "IMPL 2.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A procedure for dealing with violations of these obligations is described.",
"link": "{{LINK:R05#2.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-14"
]
},
{
"id": "2.1.3-M1",
"policy": "R05",
"control": "2.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 2.1.3-M1",
"impl_anchor": "IMPL 2.1.3",
"condition": null,
"requirement": "Employees are trained and made aware.",
"link": "{{LINK:R05#2.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-12"
]
},
{
"id": "2.1.3-S1",
"policy": "R05",
"control": "2.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.3-S1",
"impl_anchor": "IMPL 2.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A concept for the awareness and training of employees is created.",
"link": "{{LINK:R05#2.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-12"
]
},
{
"id": "2.1.3-S2",
"policy": "R05",
"control": "2.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.3-S2",
"impl_anchor": "IMPL 2.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Target groups for training and awareness measures (e.g. managers, administrators, employees with access to customer networks, production personnel) are identified and taken into account in the concept.",
"link": "{{LINK:R05#2.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.3-S3",
"policy": "R05",
"control": "2.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.3-S3",
"impl_anchor": "IMPL 2.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The concept is approved by the responsible management.",
"link": "{{LINK:R05#2.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.3-S4",
"policy": "R05",
"control": "2.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.3-S4",
"impl_anchor": "IMPL 2.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Training and awareness measures are carried out regularly and on an ad-hoc basis.",
"link": "{{LINK:R05#2.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.3-S5",
"policy": "R05",
"control": "2.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.3-S5",
"impl_anchor": "IMPL 2.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Participation in training and awareness measures is documented.",
"link": "{{LINK:R05#2.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.3-S6",
"policy": "R05",
"control": "2.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.3-S6",
"impl_anchor": "IMPL 2.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Points of contact for information security are known to the employees.",
"link": "{{LINK:R05#2.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.4-M1",
"policy": "R06",
"control": "2.1.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 2.1.4-M1",
"impl_anchor": "IMPL 2.1.4",
"condition": null,
"requirement": "The requirements for mobile working are determined and met; the relevant aspects are taken into account.",
"link": "{{LINK:R06#2.1.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.4-S1",
"policy": "R06",
"control": "2.1.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.4-S1",
"impl_anchor": "IMPL 2.1.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The relevant aspects of mobile working are taken into account.",
"link": "{{LINK:R06#2.1.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.4-S2",
"policy": "R06",
"control": "2.1.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 2.1.4-S2",
"impl_anchor": "IMPL 2.1.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Awareness of employees.",
"link": "{{LINK:R06#2.1.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "2.1.4-H1",
"policy": "R06",
"control": "2.1.4",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 2.1.4-H1",
"impl_anchor": "IMPL 2.1.4-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Protective measures against eavesdropping and being overlooked are implemented. (C)",
"link": "{{LINK:R06#2.1.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "3.1.1-M1",
"policy": "R07",
"control": "3.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 3.1.1-M1",
"impl_anchor": "IMPL 3.1.1",
"condition": null,
"requirement": "A security zone concept including associated protective measures based on the requirements for handling information assets is in place.",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "3.1.1-M2",
"policy": "R07",
"control": "3.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 3.1.1-M2",
"impl_anchor": "IMPL 3.1.1",
"condition": null,
"requirement": "The defined protective measures are implemented.",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "3.1.1-M3",
"policy": "R07",
"control": "3.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 3.1.1-M3",
"impl_anchor": "IMPL 3.1.1",
"condition": null,
"requirement": "The code of conduct for security zones is known to all persons involved.",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "3.1.1-S1",
"policy": "R07",
"control": "3.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 3.1.1-S1",
"impl_anchor": "IMPL 3.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Procedures for granting and revoking access rights are established.",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-17"
]
},
{
"id": "3.1.1-S2",
"policy": "R07",
"control": "3.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 3.1.1-S2",
"impl_anchor": "IMPL 3.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Policies for visitor management (including registration and escorting of visitors) are defined.",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-17"
]
},
{
"id": "3.1.1-S3",
"policy": "R07",
"control": "3.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 3.1.1-S3",
"impl_anchor": "IMPL 3.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Policies for carrying and using mobile IT devices and data media (e.g. registration, labelling obligations) are defined and implemented.",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-17"
]
},
{
"id": "3.1.1-S4",
"policy": "R07",
"control": "3.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 3.1.1-S4",
"impl_anchor": "IMPL 3.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Network/infrastructure components (own or customer networks) are protected against unauthorised access.",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-17"
]
},
{
"id": "3.1.1-S5",
"policy": "R07",
"control": "3.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 3.1.1-S5",
"impl_anchor": "IMPL 3.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "External premises used for storing/processing information assets are taken into account in the zone concept (e.g. storage rooms, workshops, test tracks, data centres).",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-17"
]
},
{
"id": "3.1.1-H1",
"policy": "R07",
"control": "3.1.1",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 3.1.1-H1",
"impl_anchor": "IMPL 3.1.1-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Protective measures against simple eavesdropping and being overlooked are implemented. (C)",
"link": "{{LINK:R07#3.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "3.1.4-M1",
"policy": "R06",
"control": "3.1.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 3.1.4-M1",
"impl_anchor": "IMPL 3.1.4",
"condition": null,
"requirement": "The requirements for mobile IT devices and mobile data media are determined and met; the relevant aspects are taken into account.",
"link": "{{LINK:R06#3.1.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "3.1.4-S1",
"policy": "R06",
"control": "3.1.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 3.1.4-S1",
"impl_anchor": "IMPL 3.1.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Registration of the IT devices.",
"link": "{{LINK:R06#3.1.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "3.1.4-H1",
"policy": "R06",
"control": "3.1.4",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 3.1.4-H1",
"impl_anchor": "IMPL 3.1.4-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "General encryption of mobile data media or of the information assets stored on them. Where technically not feasible, information is protected by equivalent measures. (C, I)",
"link": "{{LINK:R06#3.1.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.1-M1",
"policy": "R08",
"control": "4.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.1-M1",
"impl_anchor": "IMPL 4.1.1",
"condition": null,
"requirement": "The requirements for handling means of identification throughout the entire lifecycle are determined and met; the relevant aspects are taken into account.",
"link": "{{LINK:R08#4.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.1-S1",
"policy": "R08",
"control": "4.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.1-S1",
"impl_anchor": "IMPL 4.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Means of identification can only be created under controlled conditions.",
"link": "{{LINK:R08#4.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-03"
]
},
{
"id": "4.1.1-H1",
"policy": "R08",
"control": "4.1.1",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 4.1.1-H1",
"impl_anchor": "IMPL 4.1.1-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "A strategy for blocking or invalidating means of identification in the event of loss is prepared and, as far as possible, implemented. (C, I, A)",
"link": "{{LINK:R08#4.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.2-M1",
"policy": "R08",
"control": "4.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.2-M1",
"impl_anchor": "IMPL 4.1.2",
"condition": null,
"requirement": "The user authentication procedures are selected on the basis of a risk assessment; possible attack scenarios (e.g. direct reachability via the internet) have been taken into account.",
"link": "{{LINK:R08#4.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.2-M2",
"policy": "R08",
"control": "4.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.2-M2",
"impl_anchor": "IMPL 4.1.2",
"condition": null,
"requirement": "State-of-the-art user authentication procedures are applied.",
"link": "{{LINK:R08#4.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.2-S1",
"policy": "R08",
"control": "4.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.2-S1",
"impl_anchor": "IMPL 4.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The authentication procedures are defined and implemented on the basis of business and security requirements.",
"link": "{{LINK:R08#4.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.2-S2",
"policy": "R08",
"control": "4.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.2-S2",
"impl_anchor": "IMPL 4.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Users are authenticated at least by strong passwords in line with established and recognised practices.",
"link": "{{LINK:R08#4.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.2-S3",
"policy": "R08",
"control": "4.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.2-S3",
"impl_anchor": "IMPL 4.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "For privileged user accounts, higher-grade procedures are used (e.g. privileged access management, two-factor authentication).",
"link": "{{LINK:R08#4.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.2-H1",
"policy": "R08",
"control": "4.1.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 4.1.2-H1",
"impl_anchor": "IMPL 4.1.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Depending on the risk assessment, authentication and access control are strengthened by supplementary measures (e.g. continuous access monitoring, strong authentication, automatic log-off, lock upon inactivity, brute-force prevention). (C, I, A)",
"link": "{{LINK:R08#4.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.2-V1",
"policy": "R08",
"control": "4.1.2",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 4.1.2-V1",
"impl_anchor": "IMPL 4.1.2-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Before accessing data with a very high protection need, users are authenticated by means of strong authentication (e.g. two-factor) in line with the state of the art. (C, I)",
"link": "{{LINK:R08#4.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-M1",
"policy": "R08",
"control": "4.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.3-M1",
"impl_anchor": "IMPL 4.1.3",
"condition": null,
"requirement": "The creation, modification and deletion of user accounts is carried out.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-03"
]
},
{
"id": "4.1.3-M2",
"policy": "R08",
"control": "4.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.3-M2",
"impl_anchor": "IMPL 4.1.3",
"condition": null,
"requirement": "Unique and personalised user accounts are used.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-M3",
"policy": "R08",
"control": "4.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.3-M3",
"impl_anchor": "IMPL 4.1.3",
"condition": null,
"requirement": "The use of shared accounts is regulated (e.g. limited to cases where traceability is dispensable).",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-M4",
"policy": "R08",
"control": "4.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.3-M4",
"impl_anchor": "IMPL 4.1.3",
"condition": null,
"requirement": "User accounts are deactivated immediately after the user leaves (e.g. upon end of contract).",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-M5",
"policy": "R08",
"control": "4.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.3-M5",
"impl_anchor": "IMPL 4.1.3",
"condition": null,
"requirement": "User accounts are reviewed regularly.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-M6",
"policy": "R08",
"control": "4.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.3-M6",
"impl_anchor": "IMPL 4.1.3",
"condition": null,
"requirement": "The log-on information is provided to the user in a secure manner.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-M7",
"policy": "R08",
"control": "4.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.1.3-M7",
"impl_anchor": "IMPL 4.1.3",
"condition": null,
"requirement": "A policy for handling log-on information is defined and implemented; the relevant aspects are taken into account.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S1",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S1",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A base account with minimal access rights and functionalities exists and is used.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S10",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S10",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Interactive log-on for service accounts (technical accounts) is prevented technically.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S2",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S2",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Default accounts and passwords preconfigured by the manufacturer are deactivated (e.g. blocking or password change).",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S3",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S3",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "User accounts are created or authorised by the responsible body.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S4",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S4",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The creation of user accounts is subject to an approval process (four-eyes principle).",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S5",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S5",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "User accounts of service providers are deactivated after completion of their task.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S6",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S6",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Deadlines for deactivating and deleting user accounts are defined.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S7",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S7",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The use of default passwords is prevented technically.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S8",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S8",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "In the case of strong authentication, the use of the medium (e.g. possession factor) is secure.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.1.3-S9",
"policy": "R08",
"control": "4.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.1.3-S9",
"impl_anchor": "IMPL 4.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "User accounts are reviewed regularly; this also includes accounts in customers' IT systems.",
"link": "{{LINK:R08#4.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.2.1-M1",
"policy": "R08",
"control": "4.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.2.1-M1",
"impl_anchor": "IMPL 4.2.1",
"condition": null,
"requirement": "The requirements for managing access rights (authorisation) are determined and met; the relevant aspects are taken into account.",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-03"
]
},
{
"id": "4.2.1-M2",
"policy": "R08",
"control": "4.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 4.2.1-M2",
"impl_anchor": "IMPL 4.2.1",
"condition": null,
"requirement": "The access rights granted for normal and privileged user accounts as well as technical accounts are reviewed regularly, also in customers' IT systems.",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-03"
]
},
{
"id": "4.2.1-S1",
"policy": "R08",
"control": "4.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.2.1-S1",
"impl_anchor": "IMPL 4.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Strategies for authorising access to information are prepared.",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-03"
]
},
{
"id": "4.2.1-S2",
"policy": "R08",
"control": "4.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.2.1-S2",
"impl_anchor": "IMPL 4.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Authorisation roles are used.",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.2.1-S3",
"policy": "R08",
"control": "4.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.2.1-S3",
"impl_anchor": "IMPL 4.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Rights are granted according to the need-to-use principle and in line with role and/or area of responsibility.",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.2.1-S4",
"policy": "R08",
"control": "4.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.2.1-S4",
"impl_anchor": "IMPL 4.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Normal user accounts do not receive privileged access rights.",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.2.1-S5",
"policy": "R08",
"control": "4.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 4.2.1-S5",
"impl_anchor": "IMPL 4.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The user's access rights are updated after a change in their responsibilities.",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.2.1-H1",
"policy": "R08",
"control": "4.2.1",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 4.2.1-H1",
"impl_anchor": "IMPL 4.2.1-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The access rights are approved by the responsible internal information officer. (C, I, A)",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.2.1-V1",
"policy": "R08",
"control": "4.2.1",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 4.2.1-V1",
"impl_anchor": "IMPL 4.2.1-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Information is stored encrypted at content level (e.g. file level) to prevent unauthorised access (including by privileged users). Where encryption is not feasible, equivalent measures apply. (C)",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "4.2.1-V2",
"policy": "R08",
"control": "4.2.1",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 4.2.1-V2",
"impl_anchor": "IMPL 4.2.1-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Existing access rights are reviewed at shorter intervals (e.g. quarterly). (C)",
"link": "{{LINK:R08#4.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.1.1-M1",
"policy": "R09",
"control": "5.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.1.1-M1",
"impl_anchor": "IMPL 5.1.1",
"condition": null,
"requirement": "All cryptographic procedures used (e.g. encryption, signature, hash algorithms, protocols) provide the security required in the respective field of application according to a recognised industry standard, as far as legally possible.",
"link": "{{LINK:R09#5.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-07"
]
},
{
"id": "5.1.1-S1",
"policy": "R09",
"control": "5.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.1.1-S1",
"impl_anchor": "IMPL 5.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A concept for the use of cryptography is defined and implemented; the relevant aspects are taken into account.",
"link": "{{LINK:R09#5.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-07"
]
},
{
"id": "5.1.1-H1",
"policy": "R09",
"control": "5.1.1",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.1.1-H1",
"impl_anchor": "IMPL 5.1.1-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Requirements for key sovereignty (in particular in the case of external processing) are determined and met. (C, I)",
"link": "{{LINK:R09#5.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.1.2-M1",
"policy": "R09",
"control": "5.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.1.2-M1",
"impl_anchor": "IMPL 5.1.2",
"condition": null,
"requirement": "The network services used for transmitting information are identified and documented.",
"link": "{{LINK:R09#5.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-07"
]
},
{
"id": "5.1.2-M2",
"policy": "R09",
"control": "5.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.1.2-M2",
"impl_anchor": "IMPL 5.1.2",
"condition": null,
"requirement": "Policies and procedures in line with the classification requirements for the use of network services are defined and implemented.",
"link": "{{LINK:R09#5.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.1.2-M3",
"policy": "R09",
"control": "5.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.1.2-M3",
"impl_anchor": "IMPL 5.1.2",
"condition": null,
"requirement": "Measures to protect transmitted content against unauthorised access are implemented.",
"link": "{{LINK:R09#5.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.1.2-S1",
"policy": "R09",
"control": "5.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.1.2-S1",
"impl_anchor": "IMPL 5.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Measures to ensure correct addressing and correct transmission of information are implemented.",
"link": "{{LINK:R09#5.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-07"
]
},
{
"id": "5.1.2-S2",
"policy": "R09",
"control": "5.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.1.2-S2",
"impl_anchor": "IMPL 5.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Electronic data exchange takes place using content or transport encryption in line with the respective classification.",
"link": "{{LINK:R09#5.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.1.2-S3",
"policy": "R09",
"control": "5.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.1.2-S3",
"impl_anchor": "IMPL 5.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Remote access connections to the organisation's network have appropriate security features; the relevant aspects are taken into account.",
"link": "{{LINK:R09#5.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.1.2-H1",
"policy": "R09",
"control": "5.1.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.1.2-H1",
"impl_anchor": "IMPL 5.1.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Information is transmitted encrypted (at least transport encryption) or protected by equivalently effective measures. (C)",
"link": "{{LINK:R09#5.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.1.2-V1",
"policy": "R09",
"control": "5.1.2",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.1.2-V1",
"impl_anchor": "IMPL 5.1.2-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Information is transmitted with content encryption. (C)",
"link": "{{LINK:R09#5.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.1-M1",
"policy": "R10",
"control": "5.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.1-M1",
"impl_anchor": "IMPL 5.2.1",
"condition": null,
"requirement": "Information security requirements for changes to the organisation, business processes and IT systems are determined and met.",
"link": "{{LINK:R10#5.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-04"
]
},
{
"id": "5.2.1-S1",
"policy": "R10",
"control": "5.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.1-S1",
"impl_anchor": "IMPL 5.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A formal approval procedure is established.",
"link": "{{LINK:R10#5.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.1-S2",
"policy": "R10",
"control": "5.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.1-S2",
"impl_anchor": "IMPL 5.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The possible effects of changes on information security are assessed.",
"link": "{{LINK:R10#5.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.1-S3",
"policy": "R10",
"control": "5.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.1-S3",
"impl_anchor": "IMPL 5.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Changes with an effect on information security are planned and tested.",
"link": "{{LINK:R10#5.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.1-S4",
"policy": "R10",
"control": "5.2.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.1-S4",
"impl_anchor": "IMPL 5.2.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Fallback procedures in the event of errors are taken into account.",
"link": "{{LINK:R10#5.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.1-H1",
"policy": "R10",
"control": "5.2.1",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.1-H1",
"impl_anchor": "IMPL 5.2.1-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Compliance with the information security requirements is verified during and after the changes. (C, I, A)",
"link": "{{LINK:R10#5.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.2-M1",
"policy": "R10",
"control": "5.2.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.2-M1",
"impl_anchor": "IMPL 5.2.2",
"condition": null,
"requirement": "The IT systems have been subjected to a risk assessment to determine the need to separate them into development, test and production systems.",
"link": "{{LINK:R10#5.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.2-M2",
"policy": "R10",
"control": "5.2.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.2-M2",
"impl_anchor": "IMPL 5.2.2",
"condition": null,
"requirement": "A segmentation is implemented on the basis of the results of the risk analysis.",
"link": "{{LINK:R10#5.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.2-S1",
"policy": "R10",
"control": "5.2.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.2-S1",
"impl_anchor": "IMPL 5.2.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The requirements for development and test environments are determined and met; the relevant aspects are taken into account.",
"link": "{{LINK:R10#5.2.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-M1",
"policy": "R10",
"control": "5.2.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.3-M1",
"impl_anchor": "IMPL 5.2.3",
"condition": null,
"requirement": "Requirements for protection against malware are determined.",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-M2",
"policy": "R10",
"control": "5.2.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.3-M2",
"impl_anchor": "IMPL 5.2.3",
"condition": null,
"requirement": "Technical and organisational measures for protection against malware are defined and implemented.",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-S1",
"policy": "R10",
"control": "5.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.3-S1",
"impl_anchor": "IMPL 5.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Unnecessary network services are deactivated.",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-S2",
"policy": "R10",
"control": "5.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.3-S2",
"impl_anchor": "IMPL 5.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Access to network services is limited to what is necessary through appropriate protective measures.",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-S3",
"policy": "R10",
"control": "5.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.3-S3",
"impl_anchor": "IMPL 5.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Protective software against malware is installed and updated automatically at regular intervals (e.g. virus scanner).",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-S4",
"policy": "R10",
"control": "5.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.3-S4",
"impl_anchor": "IMPL 5.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Received files and software are automatically checked for malware before execution (on-access scan).",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-S5",
"policy": "R10",
"control": "5.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.3-S5",
"impl_anchor": "IMPL 5.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The entire data stock of all systems is checked for malware regularly.",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-S6",
"policy": "R10",
"control": "5.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.3-S6",
"impl_anchor": "IMPL 5.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Data transmitted via central gateways (e.g. email, internet, external networks) is automatically checked by protective software.",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-S7",
"policy": "R10",
"control": "5.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.3-S7",
"impl_anchor": "IMPL 5.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Measures preventing protective software from being deactivated or modified by users are defined and implemented.",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.3-S8",
"policy": "R10",
"control": "5.2.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.3-S8",
"impl_anchor": "IMPL 5.2.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "For IT systems without protective software, alternative measures are implemented (e.g. special resilience, few services, no active users, network isolation).",
"link": "{{LINK:R10#5.2.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-M1",
"policy": "R10",
"control": "5.2.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.4-M1",
"impl_anchor": "IMPL 5.2.4",
"condition": null,
"requirement": "Information security requirements for handling event logs are determined and met.",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-13"
]
},
{
"id": "5.2.4-M2",
"policy": "R10",
"control": "5.2.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.4-M2",
"impl_anchor": "IMPL 5.2.4",
"condition": null,
"requirement": "Security-relevant requirements for logging the activities of administrators and users are determined and met.",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-M3",
"policy": "R10",
"control": "5.2.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.4-M3",
"impl_anchor": "IMPL 5.2.4",
"condition": null,
"requirement": "The IT systems used are assessed with regard to the need for logging.",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-M4",
"policy": "R10",
"control": "5.2.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.4-M4",
"impl_anchor": "IMPL 5.2.4",
"condition": null,
"requirement": "When external IT services are used, information on the monitoring options is obtained and taken into account in the assessment.",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-M5",
"policy": "R10",
"control": "5.2.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.4-M5",
"impl_anchor": "IMPL 5.2.4",
"condition": null,
"requirement": "Event logs are checked regularly for policy violations and conspicuous problems, in compliance with the permissible legal and organisational requirements.",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-S1",
"policy": "R10",
"control": "5.2.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.4-S1",
"impl_anchor": "IMPL 5.2.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A procedure for escalating relevant events to the responsible body is defined and established.",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-13"
]
},
{
"id": "5.2.4-S2",
"policy": "R10",
"control": "5.2.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.4-S2",
"impl_anchor": "IMPL 5.2.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Event logs (content and metadata) are protected against modification (e.g. by a dedicated environment).",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-S3",
"policy": "R10",
"control": "5.2.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.4-S3",
"impl_anchor": "IMPL 5.2.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Appropriate monitoring and recording of all information-security-relevant actions in the network is established.",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-H1",
"policy": "R10",
"control": "5.2.4",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.4-H1",
"impl_anchor": "IMPL 5.2.4-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Security-relevant requirements for handling event logs, e.g. contractual requirements, are determined and implemented. (C, I, A)",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-H2",
"policy": "R10",
"control": "5.2.4",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.4-H2",
"impl_anchor": "IMPL 5.2.4-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Events relating to the establishment and termination of remote access sessions (e.g. remote maintenance) are logged. (C, I, A)",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.4-V1",
"policy": "R10",
"control": "5.2.4",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.4-V1",
"impl_anchor": "IMPL 5.2.4-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Logging of every access to data with a very high protection need, as far as technically feasible and legally/organisationally permissible. (C, I)",
"link": "{{LINK:R10#5.2.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.5-M1",
"policy": "R10",
"control": "5.2.5",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.5-M1",
"impl_anchor": "IMPL 5.2.5",
"condition": null,
"requirement": "Information about technical vulnerabilities of the IT systems used is collected (e.g. manufacturer information, system audits, CVE database).",
"link": "{{LINK:R10#5.2.5}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-04",
"VA-06"
]
},
{
"id": "5.2.5-M2",
"policy": "R10",
"control": "5.2.5",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.5-M2",
"impl_anchor": "IMPL 5.2.5",
"condition": null,
"requirement": "Potentially affected IT systems and software are identified and the risk caused by the vulnerability is assessed.",
"link": "{{LINK:R10#5.2.5}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.5-M3",
"policy": "R10",
"control": "5.2.5",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.5-M3",
"impl_anchor": "IMPL 5.2.5",
"condition": null,
"requirement": "Risks arising from vulnerabilities are treated.",
"link": "{{LINK:R10#5.2.5}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.5-S1",
"policy": "R10",
"control": "5.2.5",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.5-S1",
"impl_anchor": "IMPL 5.2.5",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Appropriate patch management is defined and implemented (e.g. patch testing and installation).",
"link": "{{LINK:R10#5.2.5}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-06"
]
},
{
"id": "5.2.5-S2",
"policy": "R10",
"control": "5.2.5",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.5-S2",
"impl_anchor": "IMPL 5.2.5",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Risk-mitigating measures are implemented where necessary.",
"link": "{{LINK:R10#5.2.5}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.5-S3",
"policy": "R10",
"control": "5.2.5",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.5-S3",
"impl_anchor": "IMPL 5.2.5",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The successful installation of patches is verified in a suitable manner.",
"link": "{{LINK:R10#5.2.5}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-M1",
"policy": "R10",
"control": "5.2.6",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.6-M1",
"impl_anchor": "IMPL 5.2.6",
"condition": null,
"requirement": "Requirements for the review (audit) of IT systems or services are determined.",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-06"
]
},
{
"id": "5.2.6-M2",
"policy": "R10",
"control": "5.2.6",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.6-M2",
"impl_anchor": "IMPL 5.2.6",
"condition": null,
"requirement": "The scope of the system review is defined in good time.",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-M3",
"policy": "R10",
"control": "5.2.6",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.6-M3",
"impl_anchor": "IMPL 5.2.6",
"condition": null,
"requirement": "System or service reviews are coordinated with the operators and users of the IT systems/services.",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-M4",
"policy": "R10",
"control": "5.2.6",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.6-M4",
"impl_anchor": "IMPL 5.2.6",
"condition": null,
"requirement": "The results of system/service reviews are stored in a traceable manner and reported to the responsible management.",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-M5",
"policy": "R10",
"control": "5.2.6",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.6-M5",
"impl_anchor": "IMPL 5.2.6",
"condition": null,
"requirement": "Measures are derived from the results and implemented within an appropriate period.",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-S1",
"policy": "R10",
"control": "5.2.6",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.6-S1",
"impl_anchor": "IMPL 5.2.6",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "System and service reviews are planned taking possible security risks (e.g. disruptions) into account.",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-S2",
"policy": "R10",
"control": "5.2.6",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.6-S2",
"impl_anchor": "IMPL 5.2.6",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Regular system or service reviews are carried out; the relevant aspects are taken into account.",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-S3",
"policy": "R10",
"control": "5.2.6",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.6-S3",
"impl_anchor": "IMPL 5.2.6",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Within an appropriate period after completion of the review, a report is prepared.",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-H1",
"policy": "R10",
"control": "5.2.6",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.6-H1",
"impl_anchor": "IMPL 5.2.6-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "For critical IT systems/services, additional review requirements have been identified and are met (e.g. service-specific tests/tools and/or manual penetration tests, risk-based intervals). (A)",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.6-V1",
"policy": "R10",
"control": "5.2.6",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.6-V1",
"impl_anchor": "IMPL 5.2.6-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "IT systems and services are scanned regularly for vulnerabilities. For systems/services that cannot be scanned, suitable protective measures are to be implemented. (C, I, A)",
"link": "{{LINK:R10#5.2.6}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.7-M1",
"policy": "R10",
"control": "5.2.7",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.7-M1",
"impl_anchor": "IMPL 5.2.7",
"condition": null,
"requirement": "Requirements for the management and control of networks are determined and met.",
"link": "{{LINK:R10#5.2.7}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.7-M2",
"policy": "R10",
"control": "5.2.7",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.7-M2",
"impl_anchor": "IMPL 5.2.7",
"condition": null,
"requirement": "Requirements for network segmentation are determined and met.",
"link": "{{LINK:R10#5.2.7}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.7-S1",
"policy": "R10",
"control": "5.2.7",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.7-S1",
"impl_anchor": "IMPL 5.2.7",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Procedures for the management and control of networks are defined.",
"link": "{{LINK:R10#5.2.7}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.7-S2",
"policy": "R10",
"control": "5.2.7",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.7-S2",
"impl_anchor": "IMPL 5.2.7",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "For a risk-based network segmentation, the relevant aspects are taken into account.",
"link": "{{LINK:R10#5.2.7}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.7-H1",
"policy": "R10",
"control": "5.2.7",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.7-H1",
"impl_anchor": "IMPL 5.2.7-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Extended requirements for the management and control of networks are determined and implemented. (C, I, A)",
"link": "{{LINK:R10#5.2.7}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-M1",
"policy": "R04",
"control": "5.2.8",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.8-M1",
"impl_anchor": "IMPL 5.2.8",
"condition": null,
"requirement": "Critical IT services are identified and the business impact is taken into account.",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-02"
]
},
{
"id": "5.2.8-M2",
"policy": "R04",
"control": "5.2.8",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.8-M2",
"impl_anchor": "IMPL 5.2.8",
"condition": null,
"requirement": "Requirements and responsibilities for the continuity and recovery of these IT services are known to relevant stakeholders and fulfilled.",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-S1",
"policy": "R04",
"control": "5.2.8",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.8-S1",
"impl_anchor": "IMPL 5.2.8",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Critical IT systems are identified; the relevant aspects are taken into account.",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-02"
]
},
{
"id": "5.2.8-S2",
"policy": "R04",
"control": "5.2.8",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.8-S2",
"impl_anchor": "IMPL 5.2.8",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A continuity plan exists and is reviewed and updated regularly.",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-S3",
"policy": "R04",
"control": "5.2.8",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.8-S3",
"impl_anchor": "IMPL 5.2.8",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The continuity planning covers at least (D)DoS attacks, successful ransomware attacks and other sabotage, system failure scenarios as well as natural disasters affecting critical IT systems.",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-H1",
"policy": "R04",
"control": "5.2.8",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-H1",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The continuity planning contains predefined time frames (recovery time objective) for the resumption of operations. (A)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-H2",
"policy": "R04",
"control": "5.2.8",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-H2",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Appropriate SLAs with external service providers in line with the continuity planning are in place. (A)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-H3",
"policy": "R04",
"control": "5.2.8",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-H3",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The continuity plans include the coordination of contractually agreed communication with business partners. (A)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-H4",
"policy": "R04",
"control": "5.2.8",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-H4",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The continuity planning is tested regularly, incl. full recovery to a known state and adherence to defined target times. (A)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-H5",
"policy": "R04",
"control": "5.2.8",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-H5",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "A backup and recovery strategy for critical IT services and information is defined and implemented. (C, I, A)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-H6",
"policy": "R04",
"control": "5.2.8",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-H6",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Backups of critical IT services and information are sufficiently protected against unauthorised modification/deletion by malware. (I, A)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-H7",
"policy": "R04",
"control": "5.2.8",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-H7",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Backups of critical IT services and information are sufficiently protected against unauthorised access by malware or operators. (C, I)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-V1",
"policy": "R04",
"control": "5.2.8",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-V1",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "The continuity planning is coordinated with the continuity plans of relevant external service providers. (A)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-V2",
"policy": "R04",
"control": "5.2.8",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-V2",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "The continuation of essential core and business functions with minimal or no loss of operational continuity is possible; the relevant aspects are taken into account.",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.8-V3",
"policy": "R04",
"control": "5.2.8",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.8-V3",
"impl_anchor": "IMPL 5.2.8-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "The continuity planning is tested regularly. Test scenarios, results and lessons learned are recorded. (I, A)",
"link": "{{LINK:R04#5.2.8}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.9-M1",
"policy": "R10",
"control": "5.2.9",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.9-M1",
"impl_anchor": "IMPL 5.2.9",
"condition": null,
"requirement": "Backup concepts exist for relevant IT systems. Appropriate protective measures for the confidentiality, integrity and availability of the backups are taken into account.",
"link": "{{LINK:R10#5.2.9}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-05"
]
},
{
"id": "5.2.9-M2",
"policy": "R10",
"control": "5.2.9",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.2.9-M2",
"impl_anchor": "IMPL 5.2.9",
"condition": null,
"requirement": "Recovery concepts exist for relevant IT services.",
"link": "{{LINK:R10#5.2.9}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-05"
]
},
{
"id": "5.2.9-S1",
"policy": "R10",
"control": "5.2.9",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.2.9-S1",
"impl_anchor": "IMPL 5.2.9",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "For each relevant IT service, a backup and recovery concept exists. Dependencies between IT services and the recovery sequence are taken into account.",
"link": "{{LINK:R10#5.2.9}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-05"
]
},
{
"id": "5.2.9-H1",
"policy": "R10",
"control": "5.2.9",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.9-H1",
"impl_anchor": "IMPL 5.2.9-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Backup and recovery concepts are reviewed methodically at regular intervals. (A)",
"link": "{{LINK:R10#5.2.9}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.9-H2",
"policy": "R10",
"control": "5.2.9",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.9-H2",
"impl_anchor": "IMPL 5.2.9-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The fundamental recoverability is taken into account and tested (e.g. sample tests, test systems). (I, A)",
"link": "{{LINK:R10#5.2.9}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.9-V1",
"policy": "R10",
"control": "5.2.9",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.9-V1",
"impl_anchor": "IMPL 5.2.9-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "(Additional) backups are carried out via offline procedures, immutable backups or an isolated IAM solution. (I, A)",
"link": "{{LINK:R10#5.2.9}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.9-V2",
"policy": "R10",
"control": "5.2.9",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.9-V2",
"impl_anchor": "IMPL 5.2.9-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Recovery procedures are tested technically and methodically at regular intervals. (I, A)",
"link": "{{LINK:R10#5.2.9}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.2.9-V3",
"policy": "R10",
"control": "5.2.9",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.2.9-V3",
"impl_anchor": "IMPL 5.2.9-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Geographical redundancy is taken into account in backup and recovery concepts. (A)",
"link": "{{LINK:R10#5.2.9}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.3.1-M1",
"policy": "R11",
"control": "5.3.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.3.1-M1",
"impl_anchor": "IMPL 5.3.1",
"condition": null,
"requirement": "The information security requirements associated with the design and development of an IT service are determined and taken into account.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-M2",
"policy": "R11",
"control": "5.3.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.3.1-M2",
"impl_anchor": "IMPL 5.3.1",
"condition": null,
"requirement": "The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-M3",
"policy": "R11",
"control": "5.3.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.3.1-M3",
"impl_anchor": "IMPL 5.3.1",
"condition": null,
"requirement": "Information security requirements in connection with changes to developed IT services are taken into account.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-M4",
"policy": "R11",
"control": "5.3.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.3.1-M4",
"impl_anchor": "IMPL 5.3.1",
"condition": null,
"requirement": "System acceptance tests are carried out taking the information security requirements into account.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-S1",
"policy": "R11",
"control": "5.3.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.1-S1",
"impl_anchor": "IMPL 5.3.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Requirement specifications are created; the relevant aspects are taken into account.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-S2",
"policy": "R11",
"control": "5.3.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.1-S2",
"impl_anchor": "IMPL 5.3.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Requirement specifications are checked against the information security requirements.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-S3",
"policy": "R11",
"control": "5.3.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.1-S3",
"impl_anchor": "IMPL 5.3.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The IT service is checked for compliance with the specifications before production use.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-S4",
"policy": "R11",
"control": "5.3.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.1-S4",
"impl_anchor": "IMPL 5.3.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-S5",
"policy": "R11",
"control": "5.3.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.1-S5",
"impl_anchor": "IMPL 5.3.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Test systems receive protective measures comparable to the production environment when production data is used for testing.",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.1-V1",
"policy": "R11",
"control": "5.3.1",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 5.3.1-V1",
"impl_anchor": "IMPL 5.3.1-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A)",
"link": "{{LINK:R11#5.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.2-M1",
"policy": "R11",
"control": "5.3.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.3.2-M1",
"impl_anchor": "IMPL 5.3.2",
"condition": null,
"requirement": "Requirements for the information security of network services are determined and met.",
"link": "{{LINK:R11#5.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.2-S1",
"policy": "R11",
"control": "5.3.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.2-S1",
"impl_anchor": "IMPL 5.3.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A procedure for securing and using network services is defined and implemented.",
"link": "{{LINK:R11#5.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.2-S2",
"policy": "R11",
"control": "5.3.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.2-S2",
"impl_anchor": "IMPL 5.3.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The requirements are agreed in the form of SLAs.",
"link": "{{LINK:R11#5.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.2-S3",
"policy": "R11",
"control": "5.3.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.2-S3",
"impl_anchor": "IMPL 5.3.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Appropriate redundancy solutions are implemented.",
"link": "{{LINK:R11#5.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.2-H1",
"policy": "R11",
"control": "5.3.2",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 5.3.2-H1",
"impl_anchor": "IMPL 5.3.2-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A)",
"link": "{{LINK:R11#5.3.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-16"
]
},
{
"id": "5.3.3-S1",
"policy": "R11",
"control": "5.3.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.3-S1",
"impl_anchor": "IMPL 5.3.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A description of the termination process is in place, adapted to changes and regulated contractually.",
"link": "{{LINK:R11#5.3.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "5.3.4-M1",
"policy": "R12",
"control": "5.3.4",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 5.3.4-M1",
"impl_anchor": "IMPL 5.3.4",
"condition": null,
"requirement": "An effective separation (e.g. tenant separation) prevents unauthorised users of other organisations from accessing one's own information.",
"link": "{{LINK:R12#5.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-11"
]
},
{
"id": "5.3.4-S1",
"policy": "R12",
"control": "5.3.4",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 5.3.4-S1",
"impl_anchor": "IMPL 5.3.4",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The provider's separation concept is documented and adapted to changes; the relevant aspects are taken into account.",
"link": "{{LINK:R12#5.3.4}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-11"
]
},
{
"id": "5.3.4-KI-M1",
"policy": "R12",
"control": "5.3.4-KI",
"level": "must",
"type": "MUSS",
"is_isa": false,
"req_anchor": "REQ 5.3.4-KI-M1",
"impl_anchor": "IMPL 5.3.4-KI",
"condition": null,
"requirement": "The use of AI/GenAI services is regulated; only approved services are used.",
"link": "{{LINK:R12#5.3.4-KI}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-11"
]
},
{
"id": "5.3.4-KI-M2",
"policy": "R12",
"control": "5.3.4-KI",
"level": "must",
"type": "MUSS",
"is_isa": false,
"req_anchor": "REQ 5.3.4-KI-M2",
"impl_anchor": "IMPL 5.3.4-KI",
"condition": null,
"requirement": "The input of confidential or personal information into non-approved AI services is prohibited; the permissible data classes per service are defined.",
"link": "{{LINK:R12#5.3.4-KI}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-11"
]
},
{
"id": "5.3.4-KI-M3",
"policy": "R12",
"control": "5.3.4-KI",
"level": "must",
"type": "MUSS",
"is_isa": false,
"req_anchor": "REQ 5.3.4-KI-M3",
"impl_anchor": "IMPL 5.3.4-KI",
"condition": null,
"requirement": "For approved AI services, it is clarified and contractually ensured that inputs are not used for training or passed on.",
"link": "{{LINK:R12#5.3.4-KI}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-11"
]
},
{
"id": "5.3.4-KI-S1",
"policy": "R12",
"control": "5.3.4-KI",
"level": "should",
"type": "SOLL",
"is_isa": false,
"req_anchor": "REQ 5.3.4-KI-S1",
"impl_anchor": "IMPL 5.3.4-KI",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Results of AI services are reviewed before business-critical use (human in the loop); the use of AI is documented and regulatory requirements (e.g. EU AI Act) are taken into account.",
"link": "{{LINK:R12#5.3.4-KI}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-11"
]
},
{
"id": "6.1.1-M1",
"policy": "R13",
"control": "6.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.1-M1",
"impl_anchor": "IMPL 6.1.1",
"condition": null,
"requirement": "Contractors and partners are subjected to a security risk assessment.",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-10"
]
},
{
"id": "6.1.1-M2",
"policy": "R13",
"control": "6.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.1-M2",
"impl_anchor": "IMPL 6.1.1",
"condition": null,
"requirement": "An appropriate level of information security is ensured through contractual agreements with contractors and partners.",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-10"
]
},
{
"id": "6.1.1-M3",
"policy": "R13",
"control": "6.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.1-M3",
"impl_anchor": "IMPL 6.1.1",
"condition": null,
"requirement": "Where applicable, contractual agreements with clients/customers are passed on to contractors and partners.",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.1-S1",
"policy": "R13",
"control": "6.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.1-S1",
"impl_anchor": "IMPL 6.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors.",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-10"
]
},
{
"id": "6.1.1-S2",
"policy": "R13",
"control": "6.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.1-S2",
"impl_anchor": "IMPL 6.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Performance reports and documents from contractors and partners are reviewed.",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.1-H1",
"policy": "R13",
"control": "6.1.1",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.1-H1",
"impl_anchor": "IMPL 6.1.1-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A)",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.1-H2",
"policy": "R13",
"control": "6.1.1",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.1-H2",
"impl_anchor": "IMPL 6.1.1-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A)",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.1-H3",
"policy": "R13",
"control": "6.1.1",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.1-H3",
"impl_anchor": "IMPL 6.1.1-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A)",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.1-V1",
"policy": "R13",
"control": "6.1.1",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.1-V1",
"impl_anchor": "IMPL 6.1.1-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A)",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.1-V2",
"policy": "R13",
"control": "6.1.1",
"level": "vhigh",
"type": "SEHR HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.1-V2",
"impl_anchor": "IMPL 6.1.1-elev",
"condition": "FLAG_VERY_HIGH_PROTECTION",
"requirement": "Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A)",
"link": "{{LINK:R13#6.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.2-M1",
"policy": "R13",
"control": "6.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.2-M1",
"impl_anchor": "IMPL 6.1.2",
"condition": null,
"requirement": "The confidentiality requirements are determined and met.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-10"
]
},
{
"id": "6.1.2-M2",
"policy": "R13",
"control": "6.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.2-M2",
"impl_anchor": "IMPL 6.1.2",
"condition": null,
"requirement": "Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.2-M3",
"policy": "R13",
"control": "6.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.2-M3",
"impl_anchor": "IMPL 6.1.2",
"condition": null,
"requirement": "Valid confidentiality agreements are concluded before information requiring protection is passed on.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.2-M4",
"policy": "R13",
"control": "6.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.2-M4",
"impl_anchor": "IMPL 6.1.2",
"condition": null,
"requirement": "The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.2-S1",
"policy": "R13",
"control": "6.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.2-S1",
"impl_anchor": "IMPL 6.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Templates for confidentiality agreements are available and checked for legal applicability.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-10"
]
},
{
"id": "6.1.2-S2",
"policy": "R13",
"control": "6.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.2-S2",
"impl_anchor": "IMPL 6.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.2-S3",
"policy": "R13",
"control": "6.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.2-S3",
"impl_anchor": "IMPL 6.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.2-S4",
"policy": "R13",
"control": "6.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.2-S4",
"impl_anchor": "IMPL 6.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.2-S5",
"policy": "R13",
"control": "6.1.2",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.2-S5",
"impl_anchor": "IMPL 6.1.2",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented.",
"link": "{{LINK:R13#6.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-M1",
"policy": "R13",
"control": "6.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.3-M1",
"impl_anchor": "IMPL 6.1.3",
"condition": null,
"requirement": "The IT services concerned are identified.",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-10"
]
},
{
"id": "6.1.3-M2",
"policy": "R13",
"control": "6.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.3-M2",
"impl_anchor": "IMPL 6.1.3",
"condition": null,
"requirement": "The security requirements relevant to the IT service are determined.",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-M3",
"policy": "R13",
"control": "6.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.3-M3",
"impl_anchor": "IMPL 6.1.3",
"condition": null,
"requirement": "The organisation responsible for implementing the requirement is defined and aware of its responsibility.",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-M4",
"policy": "R13",
"control": "6.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.3-M4",
"impl_anchor": "IMPL 6.1.3",
"condition": null,
"requirement": "Mechanisms for shared responsibilities are specified and implemented.",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-M5",
"policy": "R13",
"control": "6.1.3",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 6.1.3-M5",
"impl_anchor": "IMPL 6.1.3",
"condition": null,
"requirement": "The responsible organisation fulfils its respective responsibilities.",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-S1",
"policy": "R13",
"control": "6.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.3-S1",
"impl_anchor": "IMPL 6.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements.",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-S2",
"policy": "R13",
"control": "6.1.3",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 6.1.3-S2",
"impl_anchor": "IMPL 6.1.3",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The responsible personnel is appropriately trained.",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-H1",
"policy": "R13",
"control": "6.1.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.3-H1",
"impl_anchor": "IMPL 6.1.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A)",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-H2",
"policy": "R13",
"control": "6.1.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.3-H2",
"impl_anchor": "IMPL 6.1.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The applicability of the ISA controls has been assessed and documented. (C, I, A)",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-H3",
"policy": "R13",
"control": "6.1.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.3-H3",
"impl_anchor": "IMPL 6.1.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The service configuration is included in the regular security assessments. (C, I, A)",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-H4",
"policy": "R13",
"control": "6.1.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.3-H4",
"impl_anchor": "IMPL 6.1.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A)",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "6.1.3-H5",
"policy": "R13",
"control": "6.1.3",
"level": "high",
"type": "HOCH",
"is_isa": true,
"req_anchor": "REQ 6.1.3-H5",
"impl_anchor": "IMPL 6.1.3-elev",
"condition": "FLAG_HIGH_PROTECTION",
"requirement": "The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A)",
"link": "{{LINK:R13#6.1.3}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "7.1.1-M1",
"policy": "R14",
"control": "7.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 7.1.1-M1",
"impl_anchor": "IMPL 7.1.1",
"condition": null,
"requirement": "Legal, regulatory and contractual requirements relevant to information security are determined regularly.",
"link": "{{LINK:R14#7.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-18"
]
},
{
"id": "7.1.1-M2",
"policy": "R14",
"control": "7.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 7.1.1-M2",
"impl_anchor": "IMPL 7.1.1",
"condition": null,
"requirement": "Policies for complying with the requirements are defined, implemented and communicated to the responsible persons.",
"link": "{{LINK:R14#7.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-18"
]
},
{
"id": "7.1.1-S1",
"policy": "R14",
"control": "7.1.1",
"level": "should",
"type": "SOLL",
"is_isa": true,
"req_anchor": "REQ 7.1.1-S1",
"impl_anchor": "IMPL 7.1.1",
"condition": "FLAG_INCLUDE_SHOULD",
"requirement": "The integrity of records in accordance with legal, regulatory and contractual requirements as well as business requirements is taken into account.",
"link": "{{LINK:R14#7.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-18"
]
},
{
"id": "7.1.2-M1",
"policy": "R14",
"control": "7.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 7.1.2-M1",
"impl_anchor": "IMPL 7.1.2",
"condition": null,
"requirement": "Legal and contractual information security requirements for procedures and processes when processing personal data are determined.",
"link": "{{LINK:R14#7.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-18"
]
},
{
"id": "7.1.2-M2",
"policy": "R14",
"control": "7.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 7.1.2-M2",
"impl_anchor": "IMPL 7.1.2",
"condition": null,
"requirement": "Provisions for complying with legal and contractual requirements for the protection of personal data are defined and known to the persons involved.",
"link": "{{LINK:R14#7.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-18"
]
},
{
"id": "7.1.2-M3",
"policy": "R14",
"control": "7.1.2",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 7.1.2-M3",
"impl_anchor": "IMPL 7.1.2",
"condition": null,
"requirement": "Processes and procedures for protecting personal data are taken into account in the information security management system.",
"link": "{{LINK:R14#7.1.2}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-18"
]
},
{
"id": "8.1.1-M1",
"policy": "P01",
"control": "8.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 8.1.1-M1",
"impl_anchor": "REQ 8.1.1-M1",
"condition": "FLAG_PROTOTYPE_PROTECTION",
"requirement": "Areas in which prototypes are processed or stored are protected by defined security zones and an effective perimeter.",
"implementation": "Prototype areas are designated as a dedicated security zone with access control, perimeter protection and logging.",
"link": "{{LINK:P01#8.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-20"
]
},
{
"id": "8.2.1-M1",
"policy": "P01",
"control": "8.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 8.2.1-M1",
"impl_anchor": "REQ 8.2.1-M1",
"condition": "FLAG_PROTOTYPE_PROTECTION",
"requirement": "Confidentiality obligations exist for prototypes; the associated information is classified and labelled.",
"implementation": "All persons involved with prototypes sign confidentiality agreements; prototypes are classified as confidential or higher.",
"link": "{{LINK:P01#8.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "8.3.1-M1",
"policy": "P01",
"control": "8.3.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 8.3.1-M1",
"impl_anchor": "REQ 8.3.1-M1",
"condition": "FLAG_PROTOTYPE_PROTECTION",
"requirement": "Transport and storage of prototypes are carried out according to documented protection requirements that ensure confidentiality and integrity.",
"implementation": "Transport and storage follow the procedure instruction VA-20: secured containers, logged handovers, access and visual protection.",
"link": "{{LINK:P01#8.3.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": [
"VA-20"
]
},
{
"id": "9.1.1-M1",
"policy": "D01",
"control": "9.1.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 9.1.1-M1",
"impl_anchor": "REQ 9.1.1-M1",
"condition": "FLAG_PERSONAL_DATA",
"requirement": "Responsibilities for data protection are appointed and the data protection organisation is documented.",
"implementation": "The role of data protection officer is appointed and integrated into the ISMS organisation; tasks and reporting paths are documented.",
"link": "{{LINK:D01#9.1.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
},
{
"id": "9.2.1-M1",
"policy": "D01",
"control": "9.2.1",
"level": "must",
"type": "MUSS",
"is_isa": true,
"req_anchor": "REQ 9.2.1-M1",
"impl_anchor": "REQ 9.2.1-M1",
"condition": "FLAG_PERSONAL_DATA",
"requirement": "Processing of personal data is lawful, purpose-bound and recorded in a record of processing activities.",
"implementation": "A record of processing activities is maintained; legal basis, purpose and deletion periods are documented for each processing activity.",
"link": "{{LINK:D01#9.2.1}}",
"nachweis_link": "{{LINK:NACHWEISREGISTER}}",
"verfahren": []
}
],
"verfahren": [
{
"id": "VA-01",
"title": "Incident-Response- und Meldeverfahren",
"file": "verfahren/VA-01_Incident-Response-und-Meldeverfahren.md",
"policy": "R04",
"fulfills": [
"1.6.1-M1",
"1.6.1-M2",
"1.6.2-M1",
"1.6.2-M2",
"1.6.2-S1",
"1.6.2-S2"
],
"link": "{{LINK:VA-01}}"
},
{
"id": "VA-02",
"title": "IT-Notfall- und Wiederanlaufverfahren (BCM)",
"file": "verfahren/VA-02_IT-Notfall-und-Wiederanlaufverfahren.md",
"policy": "R04",
"fulfills": [
"1.6.3-M1",
"1.6.3-S1",
"5.2.8-M1",
"5.2.8-S1"
],
"link": "{{LINK:VA-02}}"
},
{
"id": "VA-03",
"title": "Berechtigungsverfahren (Joiner/Mover/Leaver und Rezertifizierung)",
"file": "verfahren/VA-03_Berechtigungsverfahren.md",
"policy": "R08",
"fulfills": [
"4.1.1-S1",
"4.1.3-M1",
"4.2.1-M1",
"4.2.1-M2",
"4.2.1-S1"
],
"link": "{{LINK:VA-03}}"
},
{
"id": "VA-04",
"title": "Change- und Patch-Management-Verfahren",
"file": "verfahren/VA-04_Change-und-Patch-Management-Verfahren.md",
"policy": "R10",
"fulfills": [
"5.2.1-M1",
"5.2.5-M1"
],
"link": "{{LINK:VA-04}}"
},
{
"id": "VA-05",
"title": "Backup- und Restore-Verfahren",
"file": "verfahren/VA-05_Backup-und-Restore-Verfahren.md",
"policy": "R10",
"fulfills": [
"5.2.9-M1",
"5.2.9-M2",
"5.2.9-S1"
],
"link": "{{LINK:VA-05}}"
},
{
"id": "VA-06",
"title": "Schwachstellenmanagement-Verfahren",
"file": "verfahren/VA-06_Schwachstellenmanagement-Verfahren.md",
"policy": "R10",
"fulfills": [
"5.2.5-M1",
"5.2.5-S1",
"5.2.6-M1"
],
"link": "{{LINK:VA-06}}"
},
{
"id": "VA-07",
"title": "Kryptokonzept und Schlüsselverwaltung",
"file": "verfahren/VA-07_Kryptokonzept-und-Schluesselverwaltung.md",
"policy": "R09",
"fulfills": [
"5.1.1-M1",
"5.1.1-M2",
"5.1.1-S1",
"5.1.2-M1",
"5.1.2-S1"
],
"link": "{{LINK:VA-07}}"
},
{
"id": "VA-08",
"title": "Asset- und Klassifizierungsverfahren",
"file": "verfahren/VA-08_Asset-und-Klassifizierungsverfahren.md",
"policy": "R02",
"fulfills": [
"1.3.1-M1",
"1.3.1-M2",
"1.3.1-S1",
"1.3.2-M1",
"1.3.2-M2",
"1.3.2-S1"
],
"link": "{{LINK:VA-08}}"
},
{
"id": "VA-09",
"title": "Risikomanagement-Verfahren",
"file": "verfahren/VA-09_Risikomanagement-Verfahren.md",
"policy": "R03",
"fulfills": [
"1.4.1-M1",
"1.4.1-M2",
"1.4.1-M3",
"1.4.1-S1"
],
"link": "{{LINK:VA-09}}"
},
{
"id": "VA-10",
"title": "Lieferanten-Onboarding- und Bewertungsverfahren",
"file": "verfahren/VA-10_Lieferanten-Onboarding-und-Bewertung.md",
"policy": "R13",
"fulfills": [
"6.1.1-M1",
"6.1.1-M2",
"6.1.1-S1",
"6.1.2-M1",
"6.1.2-S1",
"6.1.3-M1"
],
"link": "{{LINK:VA-10}}"
},
{
"id": "VA-11",
"title": "Cloud- und KI-Freigabeverfahren",
"file": "verfahren/VA-11_Cloud-und-KI-Freigabeverfahren.md",
"policy": "R12",
"fulfills": [
"5.3.4-M1",
"5.3.4-M2",
"5.3.4-S1",
"5.3.4-KI-M1",
"5.3.4-KI-M2",
"5.3.4-KI-M3",
"5.3.4-KI-S1"
],
"link": "{{LINK:VA-11}}"
},
{
"id": "VA-12",
"title": "Awareness- und Schulungsverfahren",
"file": "verfahren/VA-12_Awareness-und-Schulungsverfahren.md",
"policy": "R05",
"fulfills": [
"2.1.3-M1",
"2.1.3-S1"
],
"link": "{{LINK:VA-12}}"
},
{
"id": "VA-13",
"title": "Logging- und Monitoring-Verfahren",
"file": "verfahren/VA-13_Logging-und-Monitoring-Verfahren.md",
"policy": "R10",
"fulfills": [
"5.2.4-M1",
"5.2.4-S1"
],
"link": "{{LINK:VA-13}}"
},
{
"id": "VA-14",
"title": "Personalsicherheit – Eignungsprüfung & sensible Tätigkeiten",
"file": "verfahren/VA-14_Personalsicherheit-Eignungspruefung.md",
"policy": "R05",
"fulfills": [
"2.1.1-M1",
"2.1.1-M2",
"2.1.1-M3",
"2.1.1-S1",
"2.1.1-S2",
"2.1.2-M1",
"2.1.2-M2",
"2.1.2-S1",
"2.1.2-S2",
"2.1.2-S3"
],
"link": "{{LINK:VA-14}}"
},
{
"id": "VA-15",
"title": "Interne Audits & Complianceprüfungen",
"file": "verfahren/VA-15_Interne-Audits-und-Compliancepruefungen.md",
"policy": "R03",
"fulfills": [
"1.5.1-M1",
"1.5.1-M2",
"1.5.1-M3",
"1.5.1-M4",
"1.5.1-M5",
"1.5.1-S1",
"1.5.2-M1",
"1.5.2-M2",
"1.5.2-S1"
],
"link": "{{LINK:VA-15}}"
},
{
"id": "VA-16",
"title": "Sichere Beschaffung, Entwicklung & Abnahme",
"file": "verfahren/VA-16_Sichere-Beschaffung-Entwicklung-und-Abnahme.md",
"policy": "R11",
"fulfills": [
"5.3.1-M1",
"5.3.1-M2",
"5.3.1-M3",
"5.3.1-M4",
"5.3.1-S1",
"5.3.1-S2",
"5.3.1-S3",
"5.3.1-S4",
"5.3.1-S5",
"5.3.1-V1",
"5.3.2-M1",
"5.3.2-S1",
"5.3.2-S2",
"5.3.2-S3",
"5.3.2-H1"
],
"link": "{{LINK:VA-16}}"
},
{
"id": "VA-17",
"title": "Zutritts- & Besuchermanagement (physisch)",
"file": "verfahren/VA-17_Zutritts-und-Besuchermanagement.md",
"policy": "R07",
"fulfills": [
"3.1.1-S1",
"3.1.1-S2",
"3.1.1-S3",
"3.1.1-S4",
"3.1.1-S5"
],
"link": "{{LINK:VA-17}}"
},
{
"id": "VA-18",
"title": "Datenschutz- & Compliance-Pflege",
"file": "verfahren/VA-18_Datenschutz-und-Compliance-Pflege.md",
"policy": "R14",
"fulfills": [
"7.1.1-M1",
"7.1.1-M2",
"7.1.1-S1",
"7.1.2-M1",
"7.1.2-M2",
"7.1.2-M3"
],
"link": "{{LINK:VA-18}}"
},
{
"id": "VA-19",
"title": "Informationssicherheit in Projekten",
"file": "verfahren/VA-19_Informationssicherheit-in-Projekten.md",
"policy": "R01",
"fulfills": [
"1.2.3-M1",
"1.2.3-S1",
"1.2.3-S2",
"1.2.3-S3",
"1.2.3-H1"
],
"link": "{{LINK:VA-19}}"
},
{
"id": "VA-20",
"title": "Prototypen-Zutritt und -Transport",
"file": "verfahren/VA-20_Prototypen-Zutritt-und-Transport.md",
"policy": "P01",
"fulfills": [
"8.1.1-M1",
"8.3.1-M1"
],
"link": "{{LINK:VA-20}}"
}
]
}