Files
craftvia/seed/isms-vorlagenpaket-v2-en/richtlinien/R12_Cloud-KI-und-externe-IT-Dienste.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

5.2 KiB

Policy Cloud, AI and External IT Services

Document information Value
Document type Policy
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Responsible {{ROLE_ISB}}
Approved by {{ROLE_MANAGEMENT}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This policy governs protection in outsourced/shared external IT services (cloud) as well as the use of AI/GenAI services. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.

2. Scope

This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).

3. Requirements and implementation

Structure per section: Requirement (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and Implementation at {{ORG_NAME}} (consolidated, to be adjusted where necessary).

3.1 Protection in shared external IT services

Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 5.3.4{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.23{{/if}}

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] An effective separation (e.g. tenant separation) prevents unauthorised users of other organisations from accessing one's own information. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] The provider's separation concept is documented and adapted to changes; the relevant aspects are taken into account. {{/if}} {{/if}}

{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}

  • [ISO A.5.23] Processes for acquisition, use, management and exit of cloud services are established in line with the information security requirements. {{/if}}

Implementation at {{ORG_NAME}}

For shared external IT services, effective tenant separation is required and contractually assured; the provider's separation concept is documented and updated upon changes.{{#if FLAG_CLOUD_USED}} Cloud services are assessed before use (protection need, data location/EU, encryption, exit) and approved by {{ROLE_ISB}}; the approvals are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}) (see {{LINK:VA-11}}).{{/if}}

{{#if FLAG_AI_USED}}

3.2 Use of AI/GenAI services (supplement R12, not ISA)

Requirement

{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}

  • [MUST] The use of AI/GenAI services is regulated; only approved services are used.
  • [MUST] The input of confidential or personal information into non-approved AI services is prohibited; the permissible data classes per service are defined.
  • [MUST] For approved AI services, it is clarified and contractually ensured that inputs are not used for training or passed on. {{#if FLAG_INCLUDE_SHOULD}}
  • [SHOULD] Results of AI services are reviewed before business-critical use (human in the loop); the use of AI is documented and regulatory requirements (e.g. EU AI Act) are taken into account. {{/if}} {{/if}}

Implementation at {{ORG_NAME}}

The use of AI/GenAI services is regulated; only services approved by {{ROLE_ISB}} (maintained in the register of external IT/cloud/AI services {{LINK:REG-EXT-SERVICES}}) may be used (see {{LINK:VA-11}}). The permissible data classes per service are defined, and the input of confidential/personal data into non-approved services is prohibited; upon approval, it is contractually ensured that inputs are not used for training or passed on. AI results are reviewed before critical use (human in the loop), the use is documented and the EU AI Act is taken into account.

{{/if}}

4. Binding nature

This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.

5. Roles and responsibilities

Role Responsibility in this policy
{{ROLE_ISB}} Approval/steering
{{ROLE_IT_LEAD}} Technical safeguarding
Business units Use of approved services

6. Review and update

This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.

7. Evidence

The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).

  • Associated procedures: {{LINK:VA-11}}
  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}
  • Evidence register: {{LINK:NACHWEISREGISTER}}
  • Further: {{LINK:R09}}, {{LINK:R11}}, {{LINK:R13}}