Files
craftvia/seed/isms-vorlagenpaket-v2-en/verfahren/VA-16_Sichere-Beschaffung-Entwicklung-und-Abnahme.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

73 lines
3.7 KiB
Markdown

# Secure Procurement, Development & Acceptance
| Document information | Value |
|-----------------------|------|
| Document type | Procedure instruction (VA-16) |
| Scope | {{ISMS_SCOPE}} |
| Organisation | {{ORG_NAME}} |
| Process owner | {{ROLE_IT_LEAD}} |
| Approved by | {{ROLE_ISB}} |
| Version | {{DOC_VERSION}} |
| Date | {{DOC_DATE}} |
| Status | {{DOC_STATUS}} |
<!-- FULFILLS 5.3.1-M1, 5.3.1-M2, 5.3.1-M3, 5.3.1-M4, 5.3.1-S1, 5.3.1-S2, 5.3.1-S3, 5.3.1-S4, 5.3.1-S5, 5.3.1-V1, 5.3.2-M1, 5.3.2-S1, 5.3.2-S2, 5.3.2-S3, 5.3.2-H1, A.8.25-1, A.8.26-1, A.8.27-1, A.8.28-1, A.8.29-1, A.8.30-1, A.8.31-1, A.8.33-1, A.8.4-1 | POLICY R11 -->
## 1. Purpose
This procedure ensures that information security requirements are an integral part of the procurement, design, development, extension and modification of IT services and systems (security by design), including acceptance tests and test data handling. It operationalises the associated policy ({{LINK:R11}}).
## 2. Scope
Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}) for the procurement, in-house/external development and modification of IT services/systems.
## 3. Trigger
Procurement, new/further development or substantial modification of an IT service/system.
## 4. Inputs
- Security/protection-need requirements; applicable ISA controls
- Test/acceptance concept
- Where applicable, external services ({{LINK:REG-EXT-SERVICES}})
## 5. Process
1. Specify security requirements (security by design) and take the protection need into account.
2. Carry out procurement/modification based on the security criteria.{{#if FLAG_EXTERNAL_IT}} External/cloud services are assessed via {{LINK:VA-11}} and maintained in the {{LINK:REG-EXT-SERVICES}}.{{/if}}
3. Acceptance tests under security aspects before production deployment; approval in {{TOOL_TICKET}} (change coupling {{LINK:VA-04}}).
4. Avoid or anonymise production data in tests; protect test systems appropriately.
5. {{#if FLAG_DEV_INHOUSE}} For in-house development, secure coding requirements apply with code reviews and automated security tests (SAST/dependency scan).{{/if}}
6. {{#if FLAG_VERY_HIGH_PROTECTION}} Where the protection need is very high, an additional independent security review/acceptance is carried out before approval.{{/if}}
## 6. RACI
| # | Step | R (Execution) | A (Accountable) | C (Consulted) | I (Informed) |
|---|---------|------------------|------------------|-----------------|----------------|
| 1 | Specify security requirements | {{ROLE_IT_LEAD}} | {{ROLE_ISB}} | Business unit | - |
| 2 | Carry out procurement/modification | {{ROLE_IT_LEAD}} | {{ROLE_IT_LEAD}} | {{ROLE_ISB}} | - |
| 3 | Security acceptance / approval | {{ROLE_IT_LEAD}} | {{ROLE_ISB}} | Business unit | - |
| 4 | Test data handling | {{ROLE_IT_LEAD}} | {{ROLE_IT_LEAD}} | {{ROLE_DPO}} | - |
| 5 | Secure coding / security tests | Development | {{ROLE_IT_LEAD}} | {{ROLE_ISB}} | - |
| 6 | Additional review (very high protection need) | Independent auditor | {{ROLE_ISB}} | {{ROLE_IT_LEAD}} | - |
## 7. Result & evidence
Acceptance records, test reports and approvals (in {{TOOL_TICKET}}). Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).
## 8. Key performance indicators (KPI)
- Share of projects with a documented security acceptance
- Critical security findings before go-live
- Share of tests without real production data
## 9. Related documents
- Associated policy: {{LINK:R11}}
- Change procedure: {{LINK:VA-04}}
- Cloud/AI approval: {{LINK:VA-11}}; register: {{LINK:REG-EXT-SERVICES}}
- Technical security baseline: {{LINK:BASELINE}}
- ISA mapping matrix: {{LINK:ISA_MAPPING}}
<!-- Erfüllt die oben unter FULFILLS gelisteten Anforderungen; Kopplung in mapping.json. Im Lesemodus nicht sichtbar. -->