Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R07_Physische-Sicherheit.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

7.8 KiB

Policy Physical Security

Document information Value
Document type Policy
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Responsible {{ROLE_IT_LEAD}}
Approved by {{ROLE_MANAGEMENT}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This policy governs physical protection through security zones, access protection and the handling of supporting utilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.

2. Scope

This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).

3. Requirements and implementation

Structure per section: Requirement (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and Implementation at {{ORG_NAME}} (consolidated, to be adjusted where necessary).

3.1 Security zones and access

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 3.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.7.1, A.7.2, A.7.3, A.7.4, A.7.6{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] A security zone concept including associated protective measures based on the requirements for handling information assets is in place.
  • [MUST] The defined protective measures are implemented.
  • [MUST] The code of conduct for security zones is known to all persons involved. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Procedures for granting and revoking access rights are established. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Policies for visitor management (including registration and escorting of visitors) are defined. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Policies for carrying and using mobile IT devices and data media (e.g. registration, labelling obligations) are defined and implemented. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Network/infrastructure components (own or customer networks) are protected against unauthorised access. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] External premises used for storing/processing information assets are taken into account in the zone concept (e.g. storage rooms, workshops, test tracks, data centres). {{/if}} {{#if FLAG_HIGH_PROTECTION}}
  • [HIGH] Protective measures against simple eavesdropping and being overlooked are implemented. (C) {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.7.1] Security perimeters are defined and used to protect areas containing information and assets.
  • [ISO A.7.2] Secure entry controls and entry points are established to restrict access to authorised persons.
  • [ISO A.7.3] Physical security for offices, rooms and facilities is designed and implemented.
  • [ISO A.7.4] Premises are continuously monitored for unauthorised physical access.
  • [ISO A.7.6] Measures for working in secure areas are defined and implemented. {{/if}}

Implementation at {{ORG_NAME}}

A security zone concept (BL-PHY-01) with implemented protective measures and a known code of conduct is in place; access rights are granted on a needs-oriented basis via {{TOOL_TICKET}}, documented and revoked when no longer needed (BL-PHY-02, process see {{LINK:VA-17}}). Visitor management, rules for mobile devices, protection of network/infrastructure components and external premises are taken into account.

{{#if FLAG_ELEVATED_PROTECTION}}

Where the protection need is high, additional protective measures against simple eavesdropping and being overlooked are implemented. {{/if}}

4. Binding nature

This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.

5. Roles and responsibilities

Role Responsibility in this policy
{{ROLE_IT_LEAD}} Zones, access, utilities
{{ROLE_ISB}} Specifications

6. Review and update

This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.

7. Evidence

The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).

  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}
  • Evidence register: {{LINK:NACHWEISREGISTER}}
  • Further: {{LINK:R02}}, {{LINK:R06}}

{{#if FLAG_FW_ISO27001}}

3.2 Environmental protection, utilities, cabling and maintenance

Requirement reference: ISO/IEC 27001 A.7.5, A.7.8, A.7.11, A.7.12, A.7.13

Requirement

  • [ISO A.7.5] Protection against physical and environmental threats is designed and implemented.
  • [ISO A.7.8] Equipment is sited securely and protected.
  • [ISO A.7.11] Facilities are protected against failure and disruption of supporting utilities such as power and air conditioning.
  • [ISO A.7.12] Power and data cabling is protected against interception, interference and damage.
  • [ISO A.7.13] Equipment is maintained properly to ensure availability and integrity.

Implementation at {{ORG_NAME}}

Sites and technical facilities are protected against physical and environmental threats (BL-PHY-03): early fire detection, protection against water and moisture, temperature and humidity monitoring in technical rooms as well as consideration of site-specific hazards. Equipment is sited so that observation, unauthorised access and environmental risks are minimised. Power and air conditioning for critical systems are designed to be uninterruptible and are tested regularly. Power and data cabling is protected against damage and unauthorised access and is documented. Equipment is maintained according to the manufacturer's specifications; maintenance is carried out only by authorised personnel, is planned and recorded, and is supervised where performed externally.

{{/if}}

{{#if FLAG_FW_ISO27001}}

3.3 Clear desk and screen lock

Requirement reference: ISO/IEC 27001 A.7.7

Requirement

  • [ISO A.7.7] Rules for a clear desk and locked screens are defined and implemented.

Implementation at {{ORG_NAME}}

Binding rules apply for a clear desk and locked screens (BL-PHY-04): protected documents and media are locked away when unattended; screens are locked when leaving the workplace and lock automatically after {{SESSION_TIMEOUT}}. Printouts are collected immediately and documents no longer required are destroyed according to their protection needs (BL-DEL-01). The rules also apply when working from home and at mobile workplaces ({{LINK:R06}}); compliance is checked on a sample basis.

{{/if}}