Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
295 lines
14 KiB
Markdown
295 lines
14 KiB
Markdown
# Policy ISMS Organisation and Roles
|
|
|
|
| Document information | Value |
|
|
|-----------------------|------|
|
|
| Document type | Policy |
|
|
| Scope | {{ISMS_SCOPE}} |
|
|
| Organisation | {{ORG_NAME}} |
|
|
| Responsible | {{ROLE_ISB}} |
|
|
| Approved by | {{ROLE_MANAGEMENT}} |
|
|
| Version | {{DOC_VERSION}} |
|
|
| Date | {{DOC_DATE}} |
|
|
| Status | {{DOC_STATUS}} |
|
|
|
|
|
|
## 1. Purpose
|
|
|
|
This policy governs the structure, steering and responsibilities of the ISMS of {{ORG_NAME}} as well as the consideration of information security in projects. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
|
|
|
|
## 2. Scope
|
|
|
|
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
|
|
|
|
## 3. Requirements and implementation
|
|
|
|
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
|
|
|
|
### 3.1 Steering of information security
|
|
|
|
<!-- FW:REF-START ORIG:(ISA 1.2.1) -->
|
|
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.2.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 5.1, A.5.4{{/if}}
|
|
<!-- FW:REF-END -->
|
|
|
|
**Requirement**
|
|
|
|
<!-- FW:TISAX-REQ-START -->
|
|
{{#if FLAG_FW_TISAX}}
|
|
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
|
|
|
<!-- REQ 1.2.1-M1 -->
|
|
- **[MUST]** The scope of the ISMS (the organisation governed by the ISMS) is defined.
|
|
<!-- REQ 1.2.1-M2 -->
|
|
- **[MUST]** The organisation's requirements for the ISMS are determined.
|
|
<!-- REQ 1.2.1-M3 -->
|
|
- **[MUST]** The organisation's management has commissioned and approved the ISMS.
|
|
<!-- REQ 1.2.1-M4 -->
|
|
- **[MUST]** The ISMS provides management with suitable means for monitoring and steering (e.g. management review).
|
|
<!-- REQ 1.2.1-M5 -->
|
|
- **[MUST]** The applicable controls are determined (e.g. ISO 27001 statement of applicability or a completed ISA catalogue).
|
|
<!-- REQ 1.2.1-M6 -->
|
|
- **[MUST]** The effectiveness of the ISMS is reviewed regularly by management.
|
|
{{/if}}
|
|
<!-- FW:TISAX-REQ-END -->
|
|
<!-- FW:ISO-REQ-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
|
|
|
<!-- REQ 5.1-1 -->
|
|
- **[ISO 5.1]** Top management demonstrates leadership and commitment with respect to the ISMS.
|
|
<!-- REQ A.5.4-1 -->
|
|
- **[ISO A.5.4]** Management requires all personnel to apply information security in accordance with the established requirements.
|
|
{{/if}}
|
|
<!-- FW:ISO-REQ-END -->
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL 1.2.1 -->
|
|
The ISMS scope, the requirements and the applicable controls (statement of applicability / ISA catalogue) are documented in the ISMS tool ({{TOOL_NAME}}). {{ROLE_MANAGEMENT}} has commissioned and approved the ISMS by management decision, provides resources and reviews its effectiveness at least {{REVIEW_CYCLE}} in a documented management review; operational steering rests with {{ROLE_ISB}}.
|
|
|
|
### 3.2 Organisation of information security
|
|
|
|
<!-- FW:REF-START ORIG:(ISA 1.2.2) -->
|
|
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.2.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 5.3, 7.1, A.5.2, A.5.3{{/if}}
|
|
<!-- FW:REF-END -->
|
|
|
|
**Requirement**
|
|
|
|
<!-- FW:TISAX-REQ-START -->
|
|
{{#if FLAG_FW_TISAX}}
|
|
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
|
|
|
<!-- REQ 1.2.2-M1 -->
|
|
- **[MUST]** Responsibilities for information security are defined, documented and assigned.
|
|
<!-- REQ 1.2.2-M2 -->
|
|
- **[MUST]** The responsible employees are defined, qualified and enabled for their task.
|
|
<!-- REQ 1.2.2-M3 -->
|
|
- **[MUST]** The necessary resources are available.
|
|
<!-- REQ 1.2.2-M4 -->
|
|
- **[MUST]** The points of contact are known within the organisation and to relevant business partners.
|
|
{{#if FLAG_INCLUDE_SHOULD}}
|
|
<!-- REQ 1.2.2-S1 -->
|
|
- **[SHOULD]** An appropriate information security structure within the organisation is defined and documented.
|
|
{{/if}}
|
|
{{#if FLAG_INCLUDE_SHOULD}}
|
|
<!-- REQ 1.2.2-S2 -->
|
|
- **[SHOULD]** Security-relevant roles that are not part of the ISMS but are relevant to information security are taken into account.
|
|
{{/if}}
|
|
{{#if FLAG_HIGH_PROTECTION}}
|
|
<!-- REQ 1.2.2-H1 -->
|
|
- **[HIGH]** An appropriate organisational separation of responsibilities is established to avoid conflicts of interest (segregation of duties). (C, I, A)
|
|
{{/if}}
|
|
{{/if}}
|
|
<!-- FW:TISAX-REQ-END -->
|
|
<!-- FW:ISO-REQ-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
|
|
|
<!-- REQ 5.3-1 -->
|
|
- **[ISO 5.3]** Responsibilities and authorities for security-relevant roles are assigned and communicated.
|
|
<!-- REQ 7.1-1 -->
|
|
- **[ISO 7.1]** The resources needed for the ISMS are determined and provided.
|
|
<!-- REQ A.5.2-1 -->
|
|
- **[ISO A.5.2]** Information security roles and responsibilities are defined and allocated.
|
|
<!-- REQ A.5.3-1 -->
|
|
- **[ISO A.5.3]** Conflicting duties and areas of responsibility are segregated to reduce unauthorised or unintentional modification and misuse.
|
|
{{/if}}
|
|
<!-- FW:ISO-REQ-END -->
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL 1.2.2 -->
|
|
Responsibilities are documented in the role/responsibility matrix and in the ISMS tool ({{TOOL_NAME}}) and made known to the role holders as well as to relevant business partners. The role {{ROLE_ISB}} is appointed, qualified, equipped with resources and authority, and reports directly to {{ROLE_MANAGEMENT}}.
|
|
|
|
{{#if FLAG_ELEVATED_PROTECTION}}
|
|
<!-- IMPL 1.2.2-elev -->
|
|
Where the protection need is high, an organisational segregation of duties (e.g. implementation vs. control) is established; unavoidable dual roles are safeguarded by compensating controls (four-eyes principle).
|
|
{{/if}}
|
|
|
|
### 3.3 Information security in projects
|
|
|
|
<!-- FW:REF-START ORIG:(ISA 1.2.3) -->
|
|
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 1.2.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.8{{/if}}
|
|
<!-- FW:REF-END -->
|
|
|
|
**Requirement**
|
|
|
|
<!-- FW:TISAX-REQ-START -->
|
|
{{#if FLAG_FW_TISAX}}
|
|
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
|
|
|
|
<!-- REQ 1.2.3-M1 -->
|
|
- **[MUST]** Projects are classified taking information security requirements into account.
|
|
{{#if FLAG_INCLUDE_SHOULD}}
|
|
<!-- REQ 1.2.3-S1 -->
|
|
- **[SHOULD]** Procedures and criteria for classifying projects are documented.
|
|
{{/if}}
|
|
{{#if FLAG_INCLUDE_SHOULD}}
|
|
<!-- REQ 1.2.3-S2 -->
|
|
- **[SHOULD]** A risk assessment following the defined procedure is carried out in an early project phase and repeated upon project changes.
|
|
{{/if}}
|
|
{{#if FLAG_INCLUDE_SHOULD}}
|
|
<!-- REQ 1.2.3-S3 -->
|
|
- **[SHOULD]** Measures are derived for identified information security risks and taken into account in the project.
|
|
{{/if}}
|
|
{{#if FLAG_HIGH_PROTECTION}}
|
|
<!-- REQ 1.2.3-H1 -->
|
|
- **[HIGH]** The derived measures are reviewed regularly during the project and reassessed when the assessment criteria change. (C, I, A)
|
|
{{/if}}
|
|
{{/if}}
|
|
<!-- FW:TISAX-REQ-END -->
|
|
<!-- FW:ISO-REQ-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
|
|
|
|
<!-- REQ A.5.8-1 -->
|
|
- **[ISO A.5.8]** Information security is integrated into project management.
|
|
{{/if}}
|
|
<!-- FW:ISO-REQ-END -->
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL 1.2.3 -->
|
|
At the outset, projects are classified with regard to their information security needs on the basis of the documented catalogue of criteria (BL-PROJ-01); classification, risk assessment and derived measures are maintained in the project register ({{LINK:REG-PROJECTS}}). In an early project phase and upon changes, a risk assessment is carried out following the procedure Information Security in Projects ({{LINK:VA-19}}); measures are tracked as tasks in {{TOOL_TICKET}} and reviewed before project completion. The project management is responsible; where the protection need is elevated, {{ROLE_ISB}} is involved.
|
|
|
|
{{#if FLAG_ELEVATED_PROTECTION}}
|
|
<!-- IMPL 1.2.3-elev -->
|
|
Where the protection need is high, the derived measures are reviewed continuously over the course of the project and reassessed when the assessment criteria change.
|
|
{{/if}}
|
|
|
|
## 4. Binding nature
|
|
|
|
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
|
|
|
|
## 5. Roles and responsibilities
|
|
|
|
| Role | Responsibility in this policy |
|
|
|-------|-------------------------------------|
|
|
| {{ROLE_MANAGEMENT}} | Commissioning, overall responsibility, management review |
|
|
| {{ROLE_ISB}} | Operational steering of the ISMS |
|
|
| {{ROLE_IT_LEAD}} | Technical implementation |
|
|
|
|
## 6. Review and update
|
|
|
|
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
|
|
|
|
## 7. Evidence
|
|
|
|
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
|
|
|
|
## 8. Related documents
|
|
|
|
- Technical security baseline: {{LINK:BASELINE}}
|
|
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
|
|
- Evidence register: {{LINK:NACHWEISREGISTER}}
|
|
- Further: {{LINK:L00}}, {{LINK:R03}}, {{LINK:R13}}
|
|
|
|
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->
|
|
<!-- FW:ISO-SECTION-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
|
|
### 3.4 Context, interested parties and scope of the ISMS
|
|
|
|
*Requirement reference:* ISO/IEC 27001 4.1, 4.2, 4.3, 4.4
|
|
|
|
**Requirement**
|
|
|
|
<!-- REQ 4.1-1 -->
|
|
- **[ISO 4.1]** Internal and external issues that affect the ability to achieve the ISMS objectives are determined and kept up to date.
|
|
<!-- REQ 4.2-1 -->
|
|
- **[ISO 4.2]** The interested parties relevant to the ISMS and their information security requirements are determined.
|
|
<!-- REQ 4.3-1 -->
|
|
- **[ISO 4.3]** The scope of the ISMS is determined considering the issues, requirements and interfaces, and maintained as documented information.
|
|
<!-- REQ 4.4-1 -->
|
|
- **[ISO 4.4]** An ISMS is established, implemented, maintained and continually improved.
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL ISO-MS-KONTEXT -->
|
|
Internal and external issues as well as the relevant interested parties and their requirements are maintained in {{TOOL_NAME}} as a context and stakeholder analysis and updated at least {{POLICY_REVIEW_CYCLE}} and upon significant change. The scope of the ISMS ({{ISMS_SCOPE}}) is documented information and names sites, processes, organisational units and IT services as well as interfaces and dependencies on third parties; exclusions are justified. The ISMS is operated according to the PDCA cycle and continually improved. Responsible: {{ROLE_ISB}}; approval: {{ROLE_MANAGEMENT}}.
|
|
|
|
{{/if}}
|
|
<!-- FW:ISO-SECTION-END -->
|
|
<!-- FW:ISO-SECTION-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
|
|
### 3.5 Planning of changes to the ISMS
|
|
|
|
*Requirement reference:* ISO/IEC 27001 6.3
|
|
|
|
**Requirement**
|
|
|
|
<!-- REQ 6.3-1 -->
|
|
- **[ISO 6.3]** Changes to the ISMS are carried out in a planned manner.
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL ISO-MS-CHANGE -->
|
|
Changes to the ISMS — scope, organisation, roles, key processes or systems — are planned, assessed before implementation and documented in {{TOOL_NAME}}. The assessment covers the purpose and potential consequences of the change, effects on risks and controls, the resources required and the assignment of responsibilities. Approval is given by {{ROLE_MANAGEMENT}}; technical changes additionally run through change management (BL-OPS-09, see {{LINK:VA-04}}).
|
|
|
|
{{/if}}
|
|
<!-- FW:ISO-SECTION-END -->
|
|
<!-- FW:ISO-SECTION-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
|
|
### 3.6 Control of documented information
|
|
|
|
*Requirement reference:* ISO/IEC 27001 7.5.1, 7.5.2, 7.5.3
|
|
|
|
**Requirement**
|
|
|
|
<!-- REQ 7.5.1-1 -->
|
|
- **[ISO 7.5.1]** The ISMS includes the documented information required by the standard and that determined as necessary.
|
|
<!-- REQ 7.5.2-1 -->
|
|
- **[ISO 7.5.2]** When creating and updating documented information, identification, format and medium as well as review and approval are ensured.
|
|
<!-- REQ 7.5.3-1 -->
|
|
- **[ISO 7.5.3]** Documented information is controlled: availability, protection, distribution, access, retention and change control.
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL ISO-MS-DOKU -->
|
|
The documented information of the ISMS is maintained in {{TOOL_NAME}}. Every document carries a title, a unique identifier, version, date, status, responsible role and approver; creation and modification pass through review and four-eyes approval (BL-GOV-03). Control ensures availability to the authorised roles, protection against unauthorised modification, managed distribution, version control with a change history and retention of superseded versions ({{RECORDS_RETENTION}}). Documents of external origin are identified and controlled in the same way. Review cycle: {{POLICY_REVIEW_CYCLE}}.
|
|
|
|
{{/if}}
|
|
<!-- FW:ISO-SECTION-END -->
|
|
<!-- FW:ISO-SECTION-START -->
|
|
{{#if FLAG_FW_ISO27001}}
|
|
|
|
### 3.7 Contact with authorities and interest groups
|
|
|
|
*Requirement reference:* ISO/IEC 27001 A.5.5, A.5.6
|
|
|
|
**Requirement**
|
|
|
|
<!-- REQ A.5.5-1 -->
|
|
- **[ISO A.5.5]** Appropriate contacts with relevant authorities are established and maintained.
|
|
<!-- REQ A.5.6-1 -->
|
|
- **[ISO A.5.6]** Appropriate contacts with special interest groups, professional forums and security associations are maintained.
|
|
|
|
**Implementation at {{ORG_NAME}}**
|
|
|
|
<!-- IMPL ISO-KONTAKTE -->
|
|
{{ROLE_ISB}} maintains a contact list of the relevant authorities and reporting bodies ({{AUTHORITY_CONTACTS}}) with responsibility, availability and reporting channel; it is checked for currency {{POLICY_REVIEW_CYCLE}} and is available in an emergency without IT access. Reporting obligations and deadlines are held in the incident procedure ({{LINK:VA-01}}). In addition, professional contacts with interest groups, forums and security associations are maintained; the resulting insights feed into the evaluation of threat intelligence.
|
|
|
|
{{/if}}
|
|
<!-- FW:ISO-SECTION-END -->
|