[VS-NfD] Produce the IT-Grundschutz mapping for APP.3.1 and CON.11.1 #230

Closed
opened 2026-07-30 01:43:58 +02:00 by fable-5 · 2 comments
Collaborator

Plan reference: 20-massnahmenplan.md -> Phase 5
ADR: ADR 0019
Effort: L (3–4 AT)
Depends on: #226, #227, #228

Context

The authority's own documentation obligation runs along these building
blocks. Supplying the mapping ourselves saves them the translation work and
prevents them from guessing wrong about us.

Current state

No IT-Grundschutz material exists in the repository.

Acceptance criteria

  • Every requirement of APP.3.1 (web applications) and CON.11.1
    (Verschlusssachen handling) is classified as product,
    operator, or not applicable, with a one-line justification.
  • Product requirements point to code, configuration or test evidence;
    operator requirements say what we hand over to enable it.
  • "Not applicable" is argued, never asserted.
  • Open requirements point at the issue that closes them, so the
    document doubles as a gap list.
  • The building-block versions used are stated (they get revised).

Out of scope

Requirements from other building blocks, and the authority's
Sicherheitskonzept.

**Plan reference:** `20-massnahmenplan.md` -> Phase 5 **ADR:** ADR 0019 **Effort:** L (3–4 AT) **Depends on:** #226, #227, #228 ## Context The authority's own documentation obligation runs along these building blocks. Supplying the mapping ourselves saves them the translation work and prevents them from guessing wrong about us. ## Current state No IT-Grundschutz material exists in the repository. ## Acceptance criteria - [ ] Every requirement of APP.3.1 (web applications) and CON.11.1 (Verschlusssachen handling) is classified as **product**, **operator**, or **not applicable**, with a one-line justification. - [ ] Product requirements point to code, configuration or test evidence; operator requirements say what we hand over to enable it. - [ ] "Not applicable" is argued, never asserted. - [ ] Open requirements point at the issue that closes them, so the document doubles as a gap list. - [ ] The building-block versions used are stated (they get revised). ## Out of scope Requirements from other building blocks, and the authority's Sicherheitskonzept.
fable-5 added this to the M30 — VS-NfD: compliance documentation milestone 2026-07-30 01:43:58 +02:00
fable-5 added the
effort:L
area:docs
vs-nfd
labels 2026-07-30 01:43:58 +02:00
Author
Collaborator

From #201 (PR #261): the audit event catalogue at docs/architecture/audit-events.md (v1.0) is the reference for the logging/audit chapter - every emittable event id with trigger, severity, actor/target semantics and fields, plus the compatibility promise and the stdout field set. The code half is the typed union in apps/api/src/audit/audit-actions.ts; audit-catalogue.test.ts keeps document and code in step.

From #201 (PR #261): the audit event catalogue at docs/architecture/audit-events.md (v1.0) is the reference for the logging/audit chapter - every emittable event id with trigger, severity, actor/target semantics and fields, plus the compatibility promise and the stdout field set. The code half is the typed union in apps/api/src/audit/audit-actions.ts; audit-catalogue.test.ts keeps document and code in step.
Author
Collaborator

Done in commit 919201d (PR #277, CI run 581 green, fast-forward merged on Stefan's standing merge instruction).

Evidence: docs/vs-nfd/80-grundschutz-mapping.md - every requirement of APP.3.1 and CON.11.1 classified as product/operator/n.a. with a justification; worked against the real Edition 2023 texts fetched from the BSI single PDFs (editions and retrieval date stated, dropped APP.3.1 requirements listed as such, CON.11.1 = 18 Basis requirements). Product rows point at code/config/test evidence; operator rows say what we hand over; n.a. rows are argued via the delimitation statement (no par. 52 security functions, no built-in remote maintenance). CON.11.1.A7 (marking) maps the whole of M26 incl. the answered question whether the electronic marking carries a security function (no - pinned by test). Open requirements point at their issues (M27/M28/M29/M32) so the document doubles as the gap list; the not-yet-commissioned external pentest is stated honestly.

Done in commit 919201d (PR #277, CI run 581 green, fast-forward merged on Stefan's standing merge instruction). Evidence: docs/vs-nfd/80-grundschutz-mapping.md - every requirement of APP.3.1 and CON.11.1 classified as product/operator/n.a. with a justification; worked against the real Edition 2023 texts fetched from the BSI single PDFs (editions and retrieval date stated, dropped APP.3.1 requirements listed as such, CON.11.1 = 18 Basis requirements). Product rows point at code/config/test evidence; operator rows say what we hand over; n.a. rows are argued via the delimitation statement (no par. 52 security functions, no built-in remote maintenance). CON.11.1.A7 (marking) maps the whole of M26 incl. the answered question whether the electronic marking carries a security function (no - pinned by test). Open requirements point at their issues (M27/M28/M29/M32) so the document doubles as the gap list; the not-yet-commissioned external pentest is stated honestly.
Sign in to join this conversation.
No project
No Assignees
1 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: stwaidele/dorfteich#230
No description provided.