Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
380 lines
11 KiB
JSON
380 lines
11 KiB
JSON
{
|
||
"$schema": "http://json-schema.org/draft-07/schema#",
|
||
"title": "ISMS Template Package v2 – Wizard Variables (VDA ISA 2027 / Information Security)",
|
||
"description": "Single source of truth for all wizard variables. Convention: UPPER_SNAKE_CASE, placeholder {{NAME}}. Feature flags control {{#if FLAG_X}} blocks. The developer generates the wizard inputs from this schema.",
|
||
"version": "2.0",
|
||
"type": "object",
|
||
"properties": {
|
||
"ORG_NAME": {
|
||
"type": "string",
|
||
"title": "Organisation (full name)",
|
||
"example": "Example Ltd"
|
||
},
|
||
"ORG_SHORT": {
|
||
"type": "string",
|
||
"title": "Organisation (short name)",
|
||
"example": "Example"
|
||
},
|
||
"ISMS_SCOPE": {
|
||
"type": "string",
|
||
"title": "Scope (short label)",
|
||
"example": "IT & Development, North Plant"
|
||
},
|
||
"ISMS_SCOPE_DESCRIPTION": {
|
||
"type": "string",
|
||
"title": "Scope (description)"
|
||
},
|
||
"ROLE_MANAGEMENT": {
|
||
"type": "string",
|
||
"title": "Top management",
|
||
"default": "Management"
|
||
},
|
||
"ROLE_ISB": {
|
||
"type": "string",
|
||
"title": "Information Security Officer / CISO",
|
||
"default": "Information Security Officer (ISO)"
|
||
},
|
||
"ROLE_IT_LEAD": {
|
||
"type": "string",
|
||
"title": "IT management",
|
||
"default": "IT management"
|
||
},
|
||
"ROLE_HR_LEAD": {
|
||
"type": "string",
|
||
"title": "HR management",
|
||
"default": "HR management"
|
||
},
|
||
"ROLE_DPO": {
|
||
"type": "string",
|
||
"title": "Data Protection Officer",
|
||
"default": "Data Protection Officer (DPO)"
|
||
},
|
||
"DOC_VERSION": {
|
||
"type": "string",
|
||
"title": "Version",
|
||
"default": "1.0"
|
||
},
|
||
"DOC_DATE": {
|
||
"type": "string",
|
||
"title": "Date",
|
||
"format": "date"
|
||
},
|
||
"DOC_STATUS": {
|
||
"type": "string",
|
||
"title": "Status",
|
||
"enum": [
|
||
"Draft",
|
||
"In review",
|
||
"Approved"
|
||
],
|
||
"default": "Draft"
|
||
},
|
||
"TOOL_NAME": {
|
||
"type": "string",
|
||
"title": "Name of the ISMS tool",
|
||
"default": "ISMS tool"
|
||
},
|
||
"REVIEW_CYCLE": {
|
||
"type": "string",
|
||
"title": "Review cycle (free text)",
|
||
"default": "annually"
|
||
},
|
||
"TECH_MFA": {
|
||
"type": "string",
|
||
"title": "MFA solution",
|
||
"default": "the MFA solution in use"
|
||
},
|
||
"TECH_MALWARE": {
|
||
"type": "string",
|
||
"title": "Malware protection solution",
|
||
"default": "the endpoint protection solution in use"
|
||
},
|
||
"TECH_BACKUP": {
|
||
"type": "string",
|
||
"title": "Backup solution",
|
||
"default": "the backup solution in use"
|
||
},
|
||
"TECH_SIEM": {
|
||
"type": "string",
|
||
"title": "Logging/SIEM solution",
|
||
"default": "the central logging"
|
||
},
|
||
"TECH_MDM": {
|
||
"type": "string",
|
||
"title": "MDM solution",
|
||
"default": "the MDM in use"
|
||
},
|
||
"TECH_VPN": {
|
||
"type": "string",
|
||
"title": "VPN/remote access solution",
|
||
"default": "VPN"
|
||
},
|
||
"TECH_CRYPTO": {
|
||
"type": "string",
|
||
"title": "Cryptography requirement/standard",
|
||
"default": "current BSI/industry recommendations"
|
||
},
|
||
"TOOL_TICKET": {
|
||
"type": "string",
|
||
"title": "Ticket/workflow system (documentation location)",
|
||
"default": "ticketing system"
|
||
},
|
||
"TOOL_IAM": {
|
||
"type": "string",
|
||
"title": "Directory/IAM system",
|
||
"default": "Entra ID / Active Directory"
|
||
},
|
||
"PW_MIN_LENGTH": {
|
||
"type": "string",
|
||
"title": "Minimum password length (BL-IAM-01)",
|
||
"default": "12"
|
||
},
|
||
"PW_COMPLEXITY": {
|
||
"type": "string",
|
||
"title": "Password complexity (BL-IAM-01)",
|
||
"default": "complexity of at least 3 of 4 character categories"
|
||
},
|
||
"PW_ROTATION": {
|
||
"type": "string",
|
||
"title": "Password rotation (BL-IAM-01)",
|
||
"default": "no fixed forced rotation, change on an ad-hoc basis upon suspicion"
|
||
},
|
||
"MFA_SCOPE": {
|
||
"type": "string",
|
||
"title": "MFA scope (BL-IAM-02)",
|
||
"default": "all remote access, administrative access and cloud services"
|
||
},
|
||
"SESSION_TIMEOUT": {
|
||
"type": "string",
|
||
"title": "Session timeout (BL-IAM-03)",
|
||
"default": "15 min inactivity (privileged), 8 hours (standard)"
|
||
},
|
||
"ACCOUNT_LOCKOUT": {
|
||
"type": "string",
|
||
"title": "Account lockout (BL-IAM-04)",
|
||
"default": "temporary lock after 10 failed attempts"
|
||
},
|
||
"RECERT_FREQ": {
|
||
"type": "string",
|
||
"title": "Recertification (BL-IAM-05)",
|
||
"default": "semi-annually"
|
||
},
|
||
"TLS_MIN": {
|
||
"type": "string",
|
||
"title": "Minimum TLS (BL-CRY-01)",
|
||
"default": "TLS 1.2 (recommendation TLS 1.3)"
|
||
},
|
||
"CRYPTO_ALGO": {
|
||
"type": "string",
|
||
"title": "Permissible algorithms (BL-CRY-02)",
|
||
"default": "AES-256, RSA ≥ 3072 / ECC ≥ 256, SHA-256 or stronger"
|
||
},
|
||
"PATCH_SLA_CRIT": {
|
||
"type": "string",
|
||
"title": "Patch SLA critical (BL-OPS-01)",
|
||
"default": "within 72 hours"
|
||
},
|
||
"PATCH_SLA_HIGH": {
|
||
"type": "string",
|
||
"title": "Patch SLA high (BL-OPS-01)",
|
||
"default": "within 14 days"
|
||
},
|
||
"PATCH_SLA_STD": {
|
||
"type": "string",
|
||
"title": "Patch SLA standard (BL-OPS-01)",
|
||
"default": "in the regular monthly patch cycle"
|
||
},
|
||
"VULN_SCAN_FREQ": {
|
||
"type": "string",
|
||
"title": "Vulnerability scan (BL-OPS-02)",
|
||
"default": "monthly"
|
||
},
|
||
"MALWARE_UPDATE": {
|
||
"type": "string",
|
||
"title": "Malware update (BL-OPS-03)",
|
||
"default": "automatically several times a day"
|
||
},
|
||
"LOG_RETENTION": {
|
||
"type": "string",
|
||
"title": "Log retention (BL-OPS-04)",
|
||
"default": "90 days, up to 12 months depending on risk"
|
||
},
|
||
"BACKUP_SCHEME": {
|
||
"type": "string",
|
||
"title": "Backup scheme (BL-OPS-05)",
|
||
"default": "3-2-1 (3 copies, 2 media, 1 offline/offsite)"
|
||
},
|
||
"BACKUP_RETENTION": {
|
||
"type": "string",
|
||
"title": "Backup retention (BL-OPS-05)",
|
||
"default": "daily 30 days, monthly 12 months"
|
||
},
|
||
"BACKUP_TEST_FREQ": {
|
||
"type": "string",
|
||
"title": "Recovery test (BL-OPS-06)",
|
||
"default": "annually"
|
||
},
|
||
"PENTEST_FREQ": {
|
||
"type": "string",
|
||
"title": "Penetration test (BL-OPS-08)",
|
||
"default": "annually"
|
||
},
|
||
"FLAG_INCLUDE_SHOULD": {
|
||
"type": "boolean",
|
||
"title": "Include SHOULD requirements (maturity level 3 = true)",
|
||
"default": true
|
||
},
|
||
"FLAG_HIGH_PROTECTION": {
|
||
"type": "boolean",
|
||
"title": "Include additional requirements for HIGH protection need",
|
||
"default": false
|
||
},
|
||
"FLAG_VERY_HIGH_PROTECTION": {
|
||
"type": "boolean",
|
||
"title": "Include additional requirements for VERY HIGH protection need",
|
||
"default": false
|
||
},
|
||
"FLAG_ELEVATED_PROTECTION": {
|
||
"type": "boolean",
|
||
"title": "Derived: HIGH OR VERY_HIGH active (set by the wizard = FLAG_HIGH_PROTECTION || FLAG_VERY_HIGH_PROTECTION)",
|
||
"default": false
|
||
},
|
||
"FLAG_CLOUD_USED": {
|
||
"type": "boolean",
|
||
"title": "Cloud services in use",
|
||
"default": true
|
||
},
|
||
"FLAG_AI_USED": {
|
||
"type": "boolean",
|
||
"title": "AI/GenAI services in use",
|
||
"default": true
|
||
},
|
||
"FLAG_OT_USED": {
|
||
"type": "boolean",
|
||
"title": "Production/OT environment present",
|
||
"default": false
|
||
},
|
||
"FLAG_DEV_INHOUSE": {
|
||
"type": "boolean",
|
||
"title": "In-house software development",
|
||
"default": false
|
||
},
|
||
"FLAG_MOBILE_WORK": {
|
||
"type": "boolean",
|
||
"title": "Mobile working / home office permitted",
|
||
"default": true
|
||
},
|
||
"FLAG_MOBILE_DEVICES": {
|
||
"type": "boolean",
|
||
"title": "Mobile devices / data media in use",
|
||
"default": true
|
||
},
|
||
"FLAG_CRYPTO_PKI": {
|
||
"type": "boolean",
|
||
"title": "Own PKI / certificate management",
|
||
"default": false
|
||
},
|
||
"FLAG_EXTERNAL_IT": {
|
||
"type": "boolean",
|
||
"title": "External IT service providers used",
|
||
"default": true
|
||
},
|
||
"FLAG_PERSONAL_DATA": {
|
||
"type": "boolean",
|
||
"title": "Processing of personal data",
|
||
"default": true
|
||
},
|
||
"FLAG_CUSTOMER_SYSTEMS": {
|
||
"type": "boolean",
|
||
"title": "Access to customer systems (e.g. OEM)",
|
||
"default": false
|
||
},
|
||
"FLAG_PROTOTYPE_PROTECTION": {
|
||
"type": "boolean",
|
||
"title": "Assessment objective prototype protection active (chapter 8.x)",
|
||
"default": false
|
||
},
|
||
"FLAG_ISB_INTERNAL": {
|
||
"type": "boolean",
|
||
"title": "ISO staffed internally",
|
||
"default": true
|
||
},
|
||
"FLAG_ISB_EXTERNAL": {
|
||
"type": "boolean",
|
||
"title": "ISO staffed externally (external service provider)",
|
||
"default": false
|
||
},
|
||
"FLAG_FW_TISAX": {
|
||
"type": "boolean",
|
||
"title": "Framework: apply TISAX / VDA ISA",
|
||
"default": true
|
||
},
|
||
"FLAG_FW_ISO27001": {
|
||
"type": "boolean",
|
||
"title": "Framework: apply ISO/IEC 27001",
|
||
"default": false
|
||
},
|
||
"POLICY_REVIEW_CYCLE": {
|
||
"type": "string",
|
||
"title": "Review cycle for the policy and thematic policies",
|
||
"example": "annually",
|
||
"default": "annually"
|
||
},
|
||
"MGMT_REVIEW_CYCLE": {
|
||
"type": "string",
|
||
"title": "Management review interval",
|
||
"example": "annually",
|
||
"default": "annually"
|
||
},
|
||
"RISK_REVIEW_CYCLE": {
|
||
"type": "string",
|
||
"title": "Risk assessment interval",
|
||
"example": "annually",
|
||
"default": "annually"
|
||
},
|
||
"RECORDS_RETENTION": {
|
||
"type": "string",
|
||
"title": "Retention of superseded document versions",
|
||
"example": "3 years",
|
||
"default": "3 years"
|
||
},
|
||
"AUTHORITY_CONTACTS": {
|
||
"type": "string",
|
||
"title": "Relevant authorities and reporting bodies",
|
||
"example": "data protection authority, police, national CERT",
|
||
"default": "data protection authority, police, national CERT"
|
||
},
|
||
"THREAT_INTEL_SOURCES": {
|
||
"type": "string",
|
||
"title": "Sources of threat intelligence",
|
||
"example": "national CERT advisories, vendor bulletins, CVE feeds",
|
||
"default": "national CERT advisories, vendor bulletins, CVE feeds"
|
||
},
|
||
"CAPACITY_REVIEW_FREQ": {
|
||
"type": "string",
|
||
"title": "Capacity monitoring interval",
|
||
"example": "monthly",
|
||
"default": "monthly"
|
||
},
|
||
"NTP_SOURCES": {
|
||
"type": "string",
|
||
"title": "Approved time sources",
|
||
"example": "two independent, trusted NTP sources",
|
||
"default": "two independent, trusted NTP sources"
|
||
},
|
||
"DLP_SCOPE": {
|
||
"type": "string",
|
||
"title": "Channels covered against data leakage",
|
||
"example": "e-mail, removable media, cloud storage",
|
||
"default": "e-mail, removable media, cloud storage"
|
||
}
|
||
},
|
||
"required": [
|
||
"ORG_NAME",
|
||
"ISMS_SCOPE",
|
||
"ISMS_SCOPE_DESCRIPTION",
|
||
"DOC_VERSION",
|
||
"DOC_DATE"
|
||
]
|
||
}
|