ISO 9001

Progress: 100%

Management System (Clauses 4–7)

IDNameApplicableLevelCompleteIntegrityPolicyPracticeProofReifegradBreiteTiefeNote
Understanding the organization and its contextUnderstanding the organization and its context•Min-OK-**---
Understanding the needs and expectations of interested partiesUnderstanding the needs and expectations of interested parties•Min-OK------Dokument vorhanden, aber nicht sofort greifbar
Determining the scope of the information security management systemDetermining the scope of the information security management system•Erw-OK------
ISMS - Establish, implement, maintain, continually improveISMS - Establish, implement, maintain, continually improve•Min-OK------
Leadership and commitment - establish objectivesLeadership and commitment - establish objectives•Min-OK------
Leadership and commitment - ensuring integration into organization's processesLeadership and commitment - ensuring integration into organization's processes•Min-OK------
L & C - ensuring needed resources are availableL & C - ensuring needed resources are available•Min-OK------
L & C - communicating importance and conforming to the ISMSL & C - communicating importance and conforming to the ISMS•Min-OK------
L & C - ensuring ISMS achieves intended outcomesL & C - ensuring ISMS achieves intended outcomes•Min-OK------
L & C - direction and supportL & C - direction and support•Min-OK------
L & C - promoting continual improvementL & C - promoting continual improvement•Min-OK------
L &C - support other relevant management rolesL &C - support other relevant management roles•Min-OK------
Policy - appropriate to purpose of organizationPolicy - appropriate to purpose of organization•SdT-OK------
Policy - includes objectivesPolicy - includes objectives•SdT-OK------
Policy - includes commitment to satisfy applicable requirementsPolicy - includes commitment to satisfy applicable requirements•SdT-OK------
Policy - includes commitment to continual improvementPolicy - includes commitment to continual improvement•Erw-OK------
Policy - be available as documented informationPolicy - be available as documented information•Erw-OK------
Policy - be communicated within the organizationPolicy - be communicated within the organization•Min-OK------
Policy - be available to interested parties, as appropriatePolicy - be available to interested parties, as appropriate•Erw-OK------
Roles - ensure that roles are assigned and communicatedRoles - ensure that roles are assigned and communicated•Min-OK------
Roles - assign responsibility and authority for ensuring ISMS conforms to standardRoles - assign responsibility and authority for ensuring ISMS conforms to standard•Min-OK------
Roles - assign responsibility for reporting on the performance of the ISMS to top managementRoles - assign responsibility for reporting on the performance of the ISMS to top management•Min-OK------
General: Risk Assessment ProcessGeneral: Risk Assessment Process----------
Risk Assessment - Risk acceptance criteriaRisk Assessment - Risk acceptance criteria•Min-OK------
Risk Assessment - Criteria for performing information security risk assessmentRisk Assessment - Criteria for performing information security risk assessment•Min-OK------
Risk Assessment - Consistent, valid and comparable resultsRisk Assessment - Consistent, valid and comparable results•Erw-OK------
Risk Assessment - C-I-A evaluationRisk Assessment - C-I-A evaluation•Erw-OK------
Risk Assessment - identify risk ownersRisk Assessment - identify risk owners•Min-OK------
Risk Assessment - assess potential consequences of risks materializingRisk Assessment - assess potential consequences of risks materializing•Min-OK------
Risk Assessment - assess realistic likelihood of occurrence of riskRisk Assessment - assess realistic likelihood of occurrence of risk•MIn-OK------
Risk Assessment - determine levels of riskRisk Assessment - determine levels of risk•Min-OK------
Risk Assessment - Comparison of results with criteria establishedRisk Assessment - Comparison of results with criteria established•Min-OK------
Risk Assessment - prioritize analyzed risks for risk treatmentRisk Assessment - prioritize analyzed risks for risk treatment•Min-OK------
retain documented information about risk assessment processretain documented information about risk assessment process•Min-OK------
General: Risk Treatment ProcessGeneral: Risk Treatment Process----------
Select risk treatment optionsSelect risk treatment options•Min-OK------
Determine required controls (any source)Determine required controls (any source)•Min-OK------
Compare determined controls with Annex A and verify that no necessary controls have been omitted.Compare determined controls with Annex A and verify that no necessary controls have been omitted.•Min-OK------
Produce SoAProduce SoA•Erw-OK------
formulate risk treatment planformulate risk treatment plan•Min-OK------
obtain risk owner approval of risk treatment plan and acceptance of residual risksobtain risk owner approval of risk treatment plan and acceptance of residual risks•Min-OK------
retain documented information about risk treatment processretain documented information about risk treatment process•Erw-OK------
General: InfoSec objectives at relevant functions and levelsGeneral: InfoSec objectives at relevant functions and levels•Erw-OK------
objectives to be consistent with information security policyobjectives to be consistent with information security policy•Erw-OK------
objectives to be measurable, if practicableobjectives to be measurable, if practicable•Erw-OK------
objective to take into account applicable IS requirements and results from risk assessmentobjective to take into account applicable IS requirements and results from risk assessment•Erw-OK------
objectives - communication of objectivesobjectives - communication of objectives•Erw-OK------
update of objectives as appropriateupdate of objectives as appropriate•Erw-OK------
retain documented information on objectivesretain documented information on objectives•Erw-OK------
achvieving objectives - determine tasksachvieving objectives - determine tasks•Erw-OK------
achvieving objectives - determine resources requiredachvieving objectives - determine resources required•Erw-OK------
achvieving objectives - determine responsibilitiesachvieving objectives - determine responsibilities•Erw-OK------
achvieving objectives - determine planned completionachvieving objectives - determine planned completion•Erw-OK------
achvieving objectives - determine method of evaluation of resultsachvieving objectives - determine method of evaluation of results•Erw-OK------
Planning of changesPlanning of changes----------
Changes to ISMS shall be carried out in a planned manner.Changes to ISMS shall be carried out in a planned manner.-Erw-OK-**---
Support - Resources - determine and provide resources needed for establishment, implementation, maintenance and continual improvement of the ISMSSupport - Resources - determine and provide resources needed for establishment, implementation, maintenance and continual improvement of the ISMS•Min-OK-~*---2 fehlende Planstellen sowie keine Security-Rollen vorhanden
Competence - determine necessary competence of persons under its control affecting IS performanceCompetence - determine necessary competence of persons under its control affecting IS performance•Min-OK-**---teilweise kein Problem, weil Schulungen durchgängig genehmigt werden.
Competence - ensure that persons are competent on the basis of education, training, or experienceCompetence - ensure that persons are competent on the basis of education, training, or experience•Min-OK-**---
Competence - where applicable, take action to acquire necessary competence and evaluate actions takenCompetence - where applicable, take action to acquire necessary competence and evaluate actions taken•Min-OK-**---
retain appropriate documented information as evidence of competenceretain appropriate documented information as evidence of competence•Min-OK-**---
Awareness - Awareness of information security policyAwareness - Awareness of information security policy•Min-OK-**---Schulungen werden durchgeführt, es gibt aber keinen Nachweis der Anwesenheit. - 2x/Jahr Derzeit werden nur neue Mitarbeiter geschult.
Awareness - General awareness of staffAwareness - General awareness of staff•Min-OK-**---
Awareness - of implications of not conforming with IS requirementsAwareness - of implications of not conforming with IS requirements•Erw-OK-**---
Communication - determine need for internal and external communicationsCommunication - determine need for internal and external communications•SdT-OK-~~---
determination - include what to communicatedetermination - include what to communicate•SdT-OK-~~---
determination - when to communicatedetermination - when to communicate•SdT-OK-~~---
determination - with whom to communicatedetermination - with whom to communicate•SdT-OK-~~---
determination - who to communicatedetermination - who to communicate•SdT-OK-~~---
determination - processes by which communication shall be effecteddetermination - processes by which communication shall be effected•SdT-OK-~~---
Documented Information - as required by StandardDocumented Information - as required by Standard•Erw-OK------
Documented information - as identified necessaryDocumented information - as identified necessary•Erw-OK------
Creating and updating - ensure identification and descriptionCreating and updating - ensure identification and description•Erw-OK-**---Confluence wird eingesetzt.
Creating and updating - ensure appropriate formatCreating and updating - ensure appropriate format•Erw-OK-**---
Creating and updating - review and approval for suitability and adequacyCreating and updating - review and approval for suitability and adequacy•Erw-OK-**---
Control of documented information - ensure availability and suitability for use, where and when neededControl of documented information - ensure availability and suitability for use, where and when needed•Erw-OK-**---
Control of documented information - ensure adequate protection (loss of confidentiality, availability, integrity)Control of documented information - ensure adequate protection (loss of confidentiality, availability, integrity)•Erw-OK-**---
Control of documented information - address distribution, access, retrieval and useControl of documented information - address distribution, access, retrieval and use•Erw-OK-**---
Control of documented information - address storage and preservation, including preservation of legibilityControl of documented information - address storage and preservation, including preservation of legibility•Erw-OK-**---
Control of documented information - address control of changes (version control)Control of documented information - address control of changes (version control)•Erw-OK-**---
Control of documented information - address retention and dispositionControl of documented information - address retention and disposition•Erw-OK-**---
Operational planning and control - Plan, implement, control processes needed to implement ISMS and implement actions from risk assessmentOperational planning and control - Plan, implement, control processes needed to implement ISMS and implement actions from risk assessment•Erw-OK-**---
Operational planning and control - Implement plans to achieve IS objectivesOperational planning and control - Implement plans to achieve IS objectives•Min-OK-**---
Operational planning and control - Keep documented information to the extent necessary to have confidence that processes are carried out as planned.Operational planning and control - Keep documented information to the extent necessary to have confidence that processes are carried out as planned.•Erw-OK-**---
Operational planning and control - organization to control planned changes and review consequences of unintended changes, take action to mitigate any adverse effects.Operational planning and control - organization to control planned changes and review consequences of unintended changes, take action to mitigate any adverse effects.•Erw-OK-**---
Operational planning and control - organization to ensure that outsourced processes are determined and controlled.Operational planning and control - organization to ensure that outsourced processes are determined and controlled.•SdT-OK-**---
IS risk assessment - perform at planned intervals or when significant changes are proposed or occur, based on risk criteria establishedIS risk assessment - perform at planned intervals or when significant changes are proposed or occur, based on risk criteria established•Min-OK------
IS risk assessment - retain documented informationIS risk assessment - retain documented information•Min-OK------
IS risk treatment - implement risk treatment planIS risk treatment - implement risk treatment plan•Min-OK-~~---Derzeit werden Security-Themen im Backlog geführt.
IS risk treatment - retain documented information of results of IS risk treatmentIS risk treatment - retain documented information of results of IS risk treatment•Min-OK-~~---
Monitoring, measurement, analysis and evaluation - Evaluate information security performance and effectiveness of the ISMS (general process)Monitoring, measurement, analysis and evaluation - Evaluate information security performance and effectiveness of the ISMS (general process)•Erw-OK------
Determine what needs to be monitored & measured, including processes and controlsDetermine what needs to be monitored & measured, including processes and controls•Erw-OK------
Determine methods for monitoring, measurement, analysis and evaluation to ensure valid results (valid = comparable and reproducible)Determine methods for monitoring, measurement, analysis and evaluation to ensure valid results (valid = comparable and reproducible)•Erw-OK------
Determine when monitoring and measuring shall be performedDetermine when monitoring and measuring shall be performed•Erw-OK------
Determine who shall monitor and measureDetermine who shall monitor and measure•Erw-OK------
Determine when the results from monitoring and measurement shall be analysed and evaluatedDetermine when the results from monitoring and measurement shall be analysed and evaluated•Erw-OK------
Determine who shall analyse and evaluate these resultsDetermine who shall analyse and evaluate these results•Erw-OK------
Internal Audit - conduct at planned intervalsInternal Audit - conduct at planned intervals•SdT-OK-~~---
ISMS conforms to org's own requirementsISMS conforms to org's own requirements•SdT-OK-~~---
ISMS conforms to requirements of StandardISMS conforms to requirements of Standard•Erw-OK-~~---
ISMS is effectively implemented and maintainedISMS is effectively implemented and maintained•SdT-OK-~~---
ISMS - plan, establish, and maintain audit program including frequency, methods, responsibilities planning requirements, and reporting.ISMS - plan, establish, and maintain audit program including frequency, methods, responsibilities planning requirements, and reporting.•SdT-OK-~~---
Audit program to consider importance of processes concernedAudit program to consider importance of processes concerned•SdT-OK-~~---
Audit program to consider results of previous auditsAudit program to consider results of previous audits•SdT-OK-~~---
Define audit criteria and scope for each auditDefine audit criteria and scope for each audit•SdT-OK-~~---
select auditors and conduct audits that ensure objectivity and impartialityselect auditors and conduct audits that ensure objectivity and impartiality•SdT-OK-~~---
ensure audit results are reported to relevant managementensure audit results are reported to relevant management•SdT-OK-~~---
retain documented information as evidence of the audit programme and audit resultsretain documented information as evidence of the audit programme and audit results•Erw-OK-~~---
Management Review - Review ISMS at planned intervals to ensure continued suitability, adequacy, and effectivenessManagement Review - Review ISMS at planned intervals to ensure continued suitability, adequacy, and effectiveness•Min-OK-~~---
review status of actions from previous management reviewsreview status of actions from previous management reviews•Min-OK-~~---
changes to internal and external issues relevant to the ISMSchanges to internal and external issues relevant to the ISMS•Min-OK-~~---
feedback on performance including trends infeedback on performance including trends in•Min-OK-~~---
nonconformities and corrective actionsnonconformities and corrective actions•Min-OK-~~---
monitoring and measurement resultsmonitoring and measurement results•Min-OK-~~---
audit resultsaudit results•Min-OK-~~---
fulfillment of information security objectivesfulfillment of information security objectives•Min-OK-~~---
feedback from interested partiesfeedback from interested parties•Min-OK-~~---
results of risk assessment and status of risk treatment planresults of risk assessment and status of risk treatment plan•Min-OK-~~---
opportunities for continual improvementopportunities for continual improvement•Min-OK-~~---
Outputs shall include decisions related to continual improvement opportunities and needs for changes to the ISMS.Outputs shall include decisions related to continual improvement opportunities and needs for changes to the ISMS.•Min-OK-~~---
retain documented information as evidence of the results of management reviewsretain documented information as evidence of the results of management reviews•Min-OK-~~---
Nonconformity and corrective action - react to nonconformity and correct itNonconformity and corrective action - react to nonconformity and correct it•Min-OK-~~---
Nonconformity and corrective action - deal with consequences of nonconformityNonconformity and corrective action - deal with consequences of nonconformity•Min-OK-~~---
Nonconformity and corrective action - Evaluate need for action to eliminate causes (root cause) of nonconformity in order to prohibit recurrence or occurrence elsewhere by:Nonconformity and corrective action - Evaluate need for action to eliminate causes (root cause) of nonconformity in order to prohibit recurrence or occurrence elsewhere by:•Min-OK-~~---
- reviewing the nonconformity- reviewing the nonconformity•Min-OK-~~---
- determining the causes of the nonconformity- determining the causes of the nonconformity•Min-OK-~~---
- determining, if similar nonconformities exist, or could potentially occur- determining, if similar nonconformities exist, or could potentially occur•Min-OK-~~---
Nonconformity and corrective action - implement any action neededNonconformity and corrective action - implement any action needed•Min-OK-~~---
Nonconformity and corrective action - review effectiveness of corrective actionNonconformity and corrective action - review effectiveness of corrective action•Min-OK-~~---
Nonconformity and corrective action - make changes to the ISMS, if necessaryNonconformity and corrective action - make changes to the ISMS, if necessary•Min-OK-~~---
Retain documented information as evidence of nature of nonconformities and subsequent actions takenRetain documented information as evidence of nature of nonconformities and subsequent actions taken•Min-OK-~~---
Retain documented information as evidence of the results of corrective actionRetain documented information as evidence of the results of corrective action•Min-OK-~~---
Continuous improval of suitability, adequacy and effectiveness of the ISMSContinuous improval of suitability, adequacy and effectiveness of the ISMS•Min-OK-**---