Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
12 KiB
Policy Supplier and Service Provider Management
| Document information | Value |
|---|---|
| Document type | Policy |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Responsible | {{ROLE_ISB}} |
| Approved by | {{ROLE_MANAGEMENT}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
1. Purpose
This policy governs ensuring information security at suppliers, confidentiality agreements and the delineation of responsibilities. It elaborates the information security policy ({{LINK:L00}}) and serves to meet the requirements of VDA ISA 2027.
2. Scope
This policy applies within the defined ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
3. Requirements and implementation
Structure per section: Requirement (1:1 from VDA ISA; [MUST]/[SHOULD] and — where the protection need applies — [HIGH]/[VERY HIGH]) and Implementation at {{ORG_NAME}} (consolidated, to be adjusted where necessary).
3.1 Information security at suppliers
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 6.1.1{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.19, A.5.22{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] Contractors and partners are subjected to a security risk assessment.
- [MUST] An appropriate level of information security is ensured through contractual agreements with contractors and partners.
- [MUST] Where applicable, contractual agreements with clients/customers are passed on to contractors and partners. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Contractors and partners are contractually obliged to pass on requirements for an appropriate level of information security to their subcontractors. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Performance reports and documents from contractors and partners are reviewed. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] It is demonstrated that the supplier's level of information security is appropriate to the protection need (e.g. reviewed questionnaire/self-disclosure, attestation, certificate, supplier audit). (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] The degree of fulfilment of the required evidence by the supplier is documented, reviewed and monitored regularly and upon changes. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] The supplier's compliance with contractual agreements is checked, documented, reviewed and monitored regularly and upon changes. (C, I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
- [VERY HIGH] The appropriate level of information security should be demonstrated by a third-party audit (an appropriate TISAX label or similar) or an appropriate supplier audit. Without an audit, management must make a risk-based decision to continue; evidence of this decision exists. (C, I, A) {{/if}} {{#if FLAG_VERY_HIGH_PROTECTION}}
- [VERY HIGH] Contractual obligations towards customers regarding transparency of supply chain risks are fulfilled. (C, I, A) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.5.19] Processes to manage the information security risks arising from supplier relationships are defined and implemented.
- [ISO A.5.22] The information security of supplier services is monitored and reviewed regularly, and changes are managed. {{/if}}
Implementation at {{ORG_NAME}}
Contractors/partners are subjected to a security risk assessment (BL-SUP-01) and contractually obliged to an appropriate level of information security (incl. passing on to subcontractors and customer requirements); the supplier register is maintained in the ISMS tool ({{TOOL_NAME}}), and performance reports are reviewed (see {{LINK:VA-10}}).
{{#if FLAG_ELEVATED_PROTECTION}}
Where the protection need is high, the supplier's level of security is demonstrated (self-disclosure/attestation/certificate/audit) and compliance is documented and monitored regularly and upon changes. {{#if FLAG_VERY_HIGH_PROTECTION}}Where the protection need is very high, the evidence is provided via a third-party audit (TISAX or similar) or a documented risk-based management decision; transparency obligations regarding supply chain risks are fulfilled.{{/if}} {{/if}}
3.2 Confidentiality agreements
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 6.1.2{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.20{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] The confidentiality requirements are determined and met.
- [MUST] Requirements and procedures for applying confidentiality agreements are known to all persons who pass on information requiring protection.
- [MUST] Valid confidentiality agreements are concluded before information requiring protection is passed on.
- [MUST] The requirements and procedures for using confidentiality agreements and for handling information requiring protection are reviewed regularly. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Templates for confidentiality agreements are available and checked for legal applicability. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Confidentiality agreements cover the persons/organisations involved, the type of information, the subject matter, the period of validity and the responsibilities of the obligated party. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Confidentiality agreements contain provisions for handling information requiring protection beyond the contractual relationship. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] Ways to demonstrate compliance (e.g. review by independent third parties or audit rights) are defined. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] A process for monitoring the period of validity of temporary confidentiality agreements and for timely renewal is defined and implemented. {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.5.20] Relevant information security requirements are agreed with each supplier and recorded contractually. {{/if}}
Implementation at {{ORG_NAME}}
Confidentiality requirements are determined and known; before information requiring protection is passed on, valid NDAs based on reviewed standard templates (process see {{LINK:VA-10}}) (with parties, type of information, subject matter, validity, responsibilities and post-contractual provisions) are concluded and stored in the ISMS tool. Requirements/procedures and periods of validity are monitored regularly, and ways to demonstrate compliance are defined.
3.3 Delineation of responsibilities
Requirement reference: {{#if FLAG_FW_TISAX}}VDA ISA 6.1.3{{/if}}{{#if FLAG_FW_ISO27001}}{{#if FLAG_FW_TISAX}} · {{/if}}ISO/IEC 27001 A.5.21{{/if}}
Requirement
{{#if FLAG_FW_TISAX}} {{#if FLAG_FW_ISO27001}}Requirements per VDA ISA 2027:{{/if}}
- [MUST] The IT services concerned are identified.
- [MUST] The security requirements relevant to the IT service are determined.
- [MUST] The organisation responsible for implementing the requirement is defined and aware of its responsibility.
- [MUST] Mechanisms for shared responsibilities are specified and implemented.
- [MUST] The responsible organisation fulfils its respective responsibilities. {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] For IT services, the configuration is designed, implemented and documented on the basis of the necessary security requirements. {{/if}} {{#if FLAG_INCLUDE_SHOULD}}
- [SHOULD] The responsible personnel is appropriately trained. {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] A list of the IT services concerned and the respective responsible IT service providers exists. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] The applicability of the ISA controls has been assessed and documented. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] The service configuration is included in the regular security assessments. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] It is demonstrated that the IT service providers fulfil their responsibility. (C, I, A) {{/if}} {{#if FLAG_HIGH_PROTECTION}}
- [HIGH] The integration into local protective measures (e.g. secure authentication mechanisms) is established and documented. (C, I, A) {{/if}} {{/if}}
{{#if FLAG_FW_ISO27001}} {{#if FLAG_FW_TISAX}}Requirements per ISO/IEC 27001:{{/if}}
- [ISO A.5.21] Processes to manage information security risks in the ICT product and service supply chain are defined and implemented. {{/if}}
Implementation at {{ORG_NAME}}
The IT services concerned and their security requirements are identified; responsibilities between the organisation and external IT service providers (incl. mechanisms for shared responsibility) are defined, known and fulfilled (see {{LINK:VA-10}}); the IT services and service providers concerned are maintained in the register of external IT/cloud/AI services ({{LINK:REG-EXT-SERVICES}}). The configuration is implemented on a requirements basis and documented, and the personnel is trained.
{{#if FLAG_ELEVATED_PROTECTION}}
Where the protection need is high, a list of the IT services and responsible service providers exists, the applicability of the ISA controls is assessed/documented, the service configuration is part of regular security assessments, the fulfilment of responsibility is demonstrated, and the integration into local protective measures is documented. {{/if}}
4. Binding nature
This policy is binding for all affected roles within the scope. Compliance is monitored by {{ROLE_ISB}}.
5. Roles and responsibilities
| Role | Responsibility in this policy |
|---|---|
| {{ROLE_ISB}} | Supplier management |
| Procurement | Contractual integration |
6. Review and update
This policy is reviewed at least {{REVIEW_CYCLE}} and on an ad-hoc basis by {{ROLE_ISB}} and approved by {{ROLE_MANAGEMENT}}.
7. Evidence
The evidence is not maintained in this document but centrally in the evidence register ({{LINK:NACHWEISREGISTER}}) and in the associated entries of the ISMS tool ({{TOOL_NAME}}).
8. Related documents
- Associated procedures: {{LINK:VA-10}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
- Evidence register: {{LINK:NACHWEISREGISTER}}
- Further: {{LINK:R01}}, {{LINK:R12}}