Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R06_Mobiles-Arbeiten-und-mobile-Geraete.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

152 lines
5.8 KiB
Markdown

# Policy Mobile Working and Mobile Devices
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs mobile working as well as the handling of mobile IT devices and data media. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
{{#if FLAG_MOBILE_WORK}}
### 3.1 Mobile working
<!-- FW:REF-START ORIG:(ISA 2.1.4) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 2.1.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.6.7{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 2.1.4-M1 -->
- **[MUST]** The requirements for mobile working are determined and met; the relevant aspects are taken into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.4-S1 -->
- **[SHOULD]** The relevant aspects of mobile working are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 2.1.4-S2 -->
- **[SHOULD]** Awareness of employees.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 2.1.4-H1 -->
- **[HIGH]** Protective measures against eavesdropping and being overlooked are implemented. (C)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.6.7-1 -->
- **[ISO A.6.7]** Security measures for working outside the organisation's premises are implemented.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 2.1.4 -->
Mobile working is defined in this policy and the associated mobile working rule (stored in {{TOOL_NAME}}) and the requirements are met; access is exclusively via {{TECH_VPN}} with MFA (BL-IAM-02) and approved, encrypted devices (BL-CRY-03). Employees are made aware (BL-HR-01).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 2.1.4-elev -->
Where the protection need is high, protective measures against eavesdropping and being overlooked are implemented (e.g. privacy screen, quiet environment, clean screen).
{{/if}}
{{/if}}
{{#if FLAG_MOBILE_DEVICES}}
### 3.2 Mobile IT devices and data media
<!-- FW:REF-START ORIG:(ISA 3.1.4) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 3.1.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.7.9, A.7.10, A.8.1{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 3.1.4-M1 -->
- **[MUST]** The requirements for mobile IT devices and mobile data media are determined and met; the relevant aspects are taken into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 3.1.4-S1 -->
- **[SHOULD]** Registration of the IT devices.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 3.1.4-H1 -->
- **[HIGH]** General encryption of mobile data media or of the information assets stored on them. Where technically not feasible, information is protected by equivalent measures. (C, I)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.7.9-1 -->
- **[ISO A.7.9]** Assets used outside the premises are protected.
<!-- REQ A.7.10-1 -->
- **[ISO A.7.10]** Storage media are protected throughout their life cycle (acquisition, use, transport, disposal) in accordance with the classification scheme.
<!-- REQ A.8.1-1 -->
- **[ISO A.8.1]** Information stored on, processed by or accessible via user endpoint devices is protected.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 3.1.4 -->
The requirements for mobile devices and data media are determined and met: devices are registered and centrally managed via {{TECH_MDM}}, only approved devices are used; loss is reported via the reporting path (R04) and {{TOOL_TICKET}}, blocking/wiping upon loss via {{TECH_MDM}} (BL-EP-02).
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 3.1.4-elev -->
Where the protection need is high, mobile data media or the information stored on them are generally encrypted (BL-CRY-03); where not feasible, equivalent protective measures apply.
{{/if}}
{{/if}}
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_ISB}} | Security requirements |
| {{ROLE_IT_LEAD}} | Technical implementation |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R05}}, {{LINK:R07}}, {{LINK:R08}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->