Files
craftvia/seed/isms-vorlagenpaket-v2-en/verfahren/VA-09_Risikomanagement-Verfahren.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

70 lines
2.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# Risk Management Procedure
| Document information | Value |
|-----------------------|------|
| Document type | Procedure instruction (VA-09) |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Process owner | {{ROLE_ISB}} |
| Approved by | {{ROLE_ISB}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
<!-- FULFILLS 1.4.1-M1, 1.4.1-M2, 1.4.1-M3, 1.4.1-S1, 6.1.1-1, 6.1.2-1, 6.1.3-1, 8.2-1, 8.3-1 | POLICY R03 -->
## 1. Purpose
This procedure governs the identification, analysis, assessment, treatment and monitoring of information security risks. It operationalises the associated policy ({{LINK:R03}}).
## 2. Scope
Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}).
## 3. Trigger
New system/project, incident, change, regular review cycle.
## 4. Inputs
- Asset/process list
- Assessment scales & acceptance thresholds
- Existing risk register
## 5. Process
1. Identify risks (assets, threats, vulnerabilities).
2. Analyse & assess (likelihood × impact) in the ISMS tool ({{TOOL_NAME}}).
3. Determine treatment (reduce/avoid/transfer/accept) and plan measures.
4. Document residual risk acceptance.
5. Monitor & update ({{REVIEW_CYCLE}} and on an ad-hoc basis).
## 6. RACI
| # | Step | R (Execution) | A (Accountable) | C (Consulted) | I (Informed) |
|---|---------|------------------|------------------|-----------------|----------------|
| 1 | Identify risks (assets, threats) | {{ROLE_ISB}} | {{ROLE_ISB}} | Asset/process owners | - |
| 2 | Analyse & assess (likelihood × impact) | {{ROLE_ISB}} | {{ROLE_ISB}} | {{ROLE_IT_LEAD}} | - |
| 3 | Determine treatment (reduce/avoid) | {{ROLE_ISB}} | {{ROLE_MANAGEMENT}} | Business unit | - |
| 4 | Document residual risk acceptance | {{ROLE_MANAGEMENT}} | {{ROLE_MANAGEMENT}} | {{ROLE_ISB}} | - |
| 5 | Monitor & update ({{REVIEW_CYCLE}}) | {{ROLE_ISB}} | {{ROLE_ISB}} | - | - |
## 7. Result & evidence
Maintained risk register with treatment plan and acceptance decisions in the ISMS tool ({{TOOL_NAME}}). Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).
## 8. Key performance indicators (KPI)
- Share of treated risks
- Overdue measures
- Up-to-dateness of the risk register
## 9. Related documents
- Associated policy: {{LINK:R03}}
- {{LINK:VA-01}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
<!-- Erfüllt die oben unter FULFILLS gelisteten Anforderungen; Kopplung in mapping.json. Im Lesemodus nicht sichtbar. -->