Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R11_Sichere-Systembeschaffung-und-Entwicklung.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

220 lines
9.6 KiB
Markdown

# Policy Secure System Procurement and Development
| Document information | Value |
|-----------------------|------|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
## 1. Purpose
This policy governs information security in procurement and development, requirements for network services as well as return and secure deletion. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
## 2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Requirements and implementation
> Structure per section: **Requirement** (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and **Implementation at {{ORG_NAME}}** (consolidated, to be adjusted where necessary).
### 3.1 Security in procurement and development
<!-- FW:REF-START ORIG:(ISA 5.3.1) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.4, A.8.25, A.8.26, A.8.27, A.8.28, A.8.29, A.8.30, A.8.33{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.3.1-M1 -->
- **[MUST]** The information security requirements associated with the design and development of an IT service are determined and taken into account.
<!-- REQ 5.3.1-M2 -->
- **[MUST]** The information security requirements associated with the procurement or extension of IT services and components are determined and taken into account.
<!-- REQ 5.3.1-M3 -->
- **[MUST]** Information security requirements in connection with changes to developed IT services are taken into account.
<!-- REQ 5.3.1-M4 -->
- **[MUST]** System acceptance tests are carried out taking the information security requirements into account.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S1 -->
- **[SHOULD]** Requirement specifications are created; the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S2 -->
- **[SHOULD]** Requirement specifications are checked against the information security requirements.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S3 -->
- **[SHOULD]** The IT service is checked for compliance with the specifications before production use.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S4 -->
- **[SHOULD]** The use of production data for test purposes is avoided as far as possible (anonymisation/pseudonymisation where applicable); the relevant aspects are taken into account.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.1-S5 -->
- **[SHOULD]** Test systems receive protective measures comparable to the production environment when production data is used for testing.
{{/if}}
{{#if FLAG_VERY_HIGH_PROTECTION}}
<!-- REQ 5.3.1-V1 -->
- **[VERY HIGH]** The security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (e.g. penetration test). (C, I, A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.4-1 -->
- **[ISO A.8.4]** Read and write access to source code, development tools and software libraries is appropriately managed.
<!-- REQ A.8.25-1 -->
- **[ISO A.8.25]** Rules for a secure development life cycle of software and systems are established and applied.
<!-- REQ A.8.26-1 -->
- **[ISO A.8.26]** Information security requirements are identified, specified and taken into account when developing or acquiring applications.
<!-- REQ A.8.27-1 -->
- **[ISO A.8.27]** Principles for engineering secure systems are established, documented and applied.
<!-- REQ A.8.28-1 -->
- **[ISO A.8.28]** Secure coding principles are applied to software development.
<!-- REQ A.8.29-1 -->
- **[ISO A.8.29]** Security testing is integrated into the development and acceptance process.
<!-- REQ A.8.30-1 -->
- **[ISO A.8.30]** Outsourced system development is directed, monitored and reviewed.
<!-- REQ A.8.33-1 -->
- **[ISO A.8.33]** Test information is selected, protected and managed with care.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.3.1 -->
Information security requirements are an integral part of the design, procurement, extension and modification of IT services (security by design); requirement specification, review and acceptance tests under security aspects are carried out following the procedure Secure Procurement/Development & Acceptance ({{LINK:VA-16}}); production deployment only after review in {{TOOL_TICKET}}. Production data in tests is avoided/anonymised, and test systems are appropriately protected.{{#if FLAG_DEV_INHOUSE}} For in-house development, secure coding requirements apply with code reviews and automated security tests (SAST/dependency scan) in accordance with {{LINK:VA-16}}.{{/if}}
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.3.1-elev -->
{{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the security of purpose-built or substantially adapted software is tested upon commissioning, upon substantial changes or regularly (penetration test).{{/if}}
{{/if}}
### 3.2 Requirements for network services
<!-- FW:REF-START ORIG:(ISA 5.3.2) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.8.21{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
<!-- REQ 5.3.2-M1 -->
- **[MUST]** Requirements for the information security of network services are determined and met.
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.2-S1 -->
- **[SHOULD]** A procedure for securing and using network services is defined and implemented.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.2-S2 -->
- **[SHOULD]** The requirements are agreed in the form of SLAs.
{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.2-S3 -->
- **[SHOULD]** Appropriate redundancy solutions are implemented.
{{/if}}
{{#if FLAG_HIGH_PROTECTION}}
<!-- REQ 5.3.2-H1 -->
- **[HIGH]** Procedures for monitoring the quality of network traffic (e.g. traffic flow analyses, availability measurements) are defined and carried out. (A)
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.8.21-1 -->
- **[ISO A.8.21]** Security mechanisms, service levels and requirements for network services are identified, implemented and monitored.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.3.2 -->
For the network services used (internal/external), security requirements are determined, agreed in SLAs and implemented via a procedure; appropriate redundancies are in place.
{{#if FLAG_ELEVATED_PROTECTION}}
<!-- IMPL 5.3.2-elev -->
Where the protection need is high, procedures for monitoring network traffic quality (traffic flow analyses, availability measurements) are defined and carried out.
{{/if}}
### 3.3 Return and secure deletion
<!-- FW:REF-START ORIG:(ISA 5.3.3) -->
*Requirement reference:* {{#if FLAG_FW_TISAX}}VDA ISA 5.3.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.11, A.7.14, A.8.10{{/if}}
<!-- FW:REF-END -->
**Requirement**
<!-- FW:TISAX-REQ-START -->
{{#if FLAG_FW_TISAX}}
{{#if FLAG_FW_ISO27001}}*Requirements per VDA ISA 2027:*{{/if}}
{{#if FLAG_INCLUDE_SHOULD}}
<!-- REQ 5.3.3-S1 -->
- **[SHOULD]** A description of the termination process is in place, adapted to changes and regulated contractually.
{{/if}}
{{/if}}
<!-- FW:TISAX-REQ-END -->
<!-- FW:ISO-REQ-START -->
{{#if FLAG_FW_ISO27001}}
{{#if FLAG_FW_TISAX}}*Requirements per ISO/IEC 27001:*{{/if}}
<!-- REQ A.5.11-1 -->
- **[ISO A.5.11]** Personnel and external users return all assets in their possession upon termination of employment or contract.
<!-- REQ A.7.14-1 -->
- **[ISO A.7.14]** Equipment containing storage media is securely sanitised before disposal or re-use.
<!-- REQ A.8.10-1 -->
- **[ISO A.8.10]** Information stored in systems and on media is deleted when no longer required.
{{/if}}
<!-- FW:ISO-REQ-END -->
**Implementation at {{ORG_NAME}}**
<!-- IMPL 5.3.3 -->
Return and secure deletion/destruction of information and assets (upon end of contract, device decommissioning) are regulated according to BL-DEL-01, agreed contractually, adapted to changes and evidenced (deletion log).
## 4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_IT_LEAD}}.
## 5. Roles and responsibilities
| Role | Responsibility in this policy |
|-------|-------------------------------------|
| {{ROLE_IT_LEAD}} | Procurement/development |
| {{ROLE_ISB}} | Security requirements |
## 6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_IT_LEAD}} and approved by {{ROLE_MANAGEMENT}}.
## 7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
## 8. Related documents
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R02}}, {{LINK:R10}}, {{LINK:R12}}
<!-- Anforderungen 1:1 aus VDA ISA 2027; Mapping (REQ/IMPL) in mapping.json ueber Hidden-Anker. Im Lesemodus nicht sichtbar. -->