Files
craftvia/seed/isms-vorlagenpaket-v2-en/verfahren/VA-19_Informationssicherheit-in-Projekten.md
T
msolarczekandClaude Opus 5 c8e6f30a27
CI / build-and-check (push) Canceled after 0s
CI / audit (push) Canceled after 0s
CI / sbom (push) Canceled after 0s
Basis: Certvia dev@a48c5fb als Fundament für Craftvia
Unveränderter Stand von certvia/dev (a48c5fb) plus Craftvia-Spezifikation
und Brandbook unter docs/craftvia/. ISMS-Module werden im Folgecommit entfernt.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-09-14 11:05:39 +02:00

3.2 KiB

Information Security in Projects

Document information Value
Document type Procedure instruction (VA-19)
Scope {{ISMS_SCOPE}}
Organisation {{ORG_NAME}}
Process owner {{ROLE_ISB}}
Approved by {{ROLE_ISB}}
Version {{DOC_VERSION}}
Date {{DOC_DATE}}
Status {{DOC_STATUS}}

1. Purpose

This procedure ensures that information security is taken into account in projects from the outset: project classification, risk assessment in an early phase and upon changes, derivation and tracking of measures as well as involvement of the ISO where the protection need is elevated. It operationalises the associated policy ({{LINK:R01}}).

2. Scope

Applies within the ISMS scope ({{ISMS_SCOPE_DESCRIPTION}}) for all projects relating to information, IT systems or business processes.

3. Trigger

Project start, substantial project change, project completion.

4. Inputs

  • Catalogue of criteria for project classification ({{LINK:BASELINE}}, BL-PROJ-01)
  • Project register ({{LINK:REG-PROJECTS}})
  • Risk assessment scale / risk register

5. Process

  1. At the outset, classify the project with regard to its information security need on the basis of the documented catalogue of criteria (BL-PROJ-01); entry in the project register ({{LINK:REG-PROJECTS}}).
  2. Carry out a risk assessment in an early project phase and upon changes (coupling with risk management {{LINK:VA-09}}).
  3. Derive measures and track them as tasks in {{TOOL_TICKET}}.
  4. {{#if FLAG_ELEVATED_PROTECTION}} Where the protection need is elevated, {{ROLE_ISB}} is involved; additional reviews/approvals take place before critical milestones.{{/if}}
  5. Before project completion, review the implementation of the measures and document it in the project register.

6. RACI

# Step R (Execution) A (Accountable) C (Consulted) I (Informed)
1 Classify the project Project management {{ROLE_ISB}} {{ROLE_ISB}} -
2 Carry out risk assessment Project management {{ROLE_ISB}} {{ROLE_IT_LEAD}} -
3 Derive & track measures Project management Project management {{ROLE_ISB}} -
4 ISO involvement (elevated protection need) {{ROLE_ISB}} {{ROLE_ISB}} Project management {{ROLE_MANAGEMENT}}
5 Final review of measures Project management {{ROLE_ISB}} - -

7. Result & evidence

Maintained project register with classification, risk assessment and measure status. Evidence is referenced in the central evidence register ({{LINK:NACHWEISREGISTER}}).

8. Key performance indicators (KPI)

  • Share of classified projects
  • Open project security measures
  • Share of projects with ISO involvement where the protection need is elevated
  • Associated policy: {{LINK:R01}}
  • Register: {{LINK:REG-PROJECTS}}
  • Risk management procedure: {{LINK:VA-09}}
  • Technical security baseline: {{LINK:BASELINE}}
  • ISA mapping matrix: {{LINK:ISA_MAPPING}}