Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
9.6 KiB
Policy Secure System Procurement and Development
| Document information | Value |
|---|---|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
1. Purpose
This policy governs information security in procurement and development, requirements for network services as well as return and secure deletion. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
3. Requirements and implementation
Structure per section: Requirement (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and Implementation at {{ORG_NAME}} (consolidated, to be adjusted where necessary).
3.1 Security in procurement and development
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.3.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.4, A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.30, A.8.33{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] The information security requirements associated with the design and development of an IT service are determined and taken into account.
- [MUST] The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account.
- [MUST] Information security requirements in connection with changes to developed IT services are taken into account.
- [MUST] System acceptance tests are carried out taking the information security requirements into account. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Requirement specifications are created; the relevant aspects are taken into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Requirement specifications are checked against the information security requirements. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] The IT service is checked for compliance with the specifications before production use. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Test systems receive protective measures comparable to the production environment when production data is used for testing. {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
- [VERY HIGH] The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.4] Read and write access to source code, development tools and software libraries is appropriately managed.
- [ISO A.8.25] Rules for a secure development life cycle of software and systems are established and applied.
- [ISO A.8.26] Information security requirements are identified, specified and taken into account when developing or acquiring applications.
- [ISO A.8.27] Principles for engineering secure systems are established, documented and applied.
- [ISO A.8.28] Secure coding principles are applied to software development.
- [ISO A.8.29] Security testing is integrated into the development and acceptance process.
- [ISO A.8.30] Outsourced system development is directed, monitored and reviewed.
- [ISO A.8.33] Test information is selected, protected and managed with care. {{/if}}
Implementation at {{ORG_NAME}}
Information security requirements are an integral part of the design, procurement, extension and modification of IT services (security by design); requirement specification, review and acceptance tests under security aspects are carried out following the procedure Secure Procurement/Development & Acceptance ({{LINK:VA-16}}); production deployment only after review in {{TOOL_TICKET}}. Production data in tests is avoided/anonymised, and test systems are appropriately protected.{{#if FLAG_DEV_INHOUSE}} For in-house development, secure coding requirements apply with code reviews and automated security tests (SAST/dependency scan) in accordance with {{LINK:VA-16}}.{{/if}}
{{#if FLAG_ELEVATED_PROTECTION}}
{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (penetration test).{{/if}} {{/if}}
3.2 Requirements for network services
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.3.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.21{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Requirements for the information security of network services are determined and met. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] A procedure for securing and using network services is defined and implemented. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] The requirements are agreed in the form of SLAs. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Appropriate redundancy solutions are implemented. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.8.21] Security mechanisms, service levels and requirements for network services are identified, implemented and monitored. {{/if}}
Implementation at {{ORG_NAME}}
For the network services used (internal/external), security requirements are determined, agreed in SLAs and implemented via a procedure; appropriate redundancies are in place.
{{#if FLAG_ELEVATED_PROTECTION}}
Where the protection need is high, procedures for monitoring network traffic quality (traffic flow analyses, availability measurements) are defined and carried out. {{/if}}
3.3 Return and secure deletion
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.3.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.11, A.7.14, A.8.10{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] A description of the termination process is in place, adapted to changes and regulated contractually. {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.5.11] Personnel and external users return all assets in their possession upon termination of employment or contract.
- [ISO A.7.14] Equipment containing storage media is securely sanitised before disposal or re-use.
- [ISO A.8.10] Information stored in systems and on media is deleted when no longer required. {{/if}}
Implementation at {{ORG_NAME}}
Return and secure deletion/destruction of information and assets (upon end of contract, device decommissioning) are regulated according to BL-DEL-01, agreed contractually, adapted to changes and evidenced (deletion log).
4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
5. Roles and responsibilities
| Role | Responsibility in this policy |
|---|---|
| {{ROLE_IT_LEAD}} | Procurement/development |
| {{ROLE_ISB}} | Security requirements |
6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
8. Related documents
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R02}}, {{LINK:R10}}, {{LINK:R12}}