[VS-NfD] Produce the IT-Grundschutz mapping for APP.3.1 and CON.11.1 #230
Labels
No Label
area:auth
area:docs
area:export
area:ops
area:storage
area:supply-chain
auth
backend
blocked
collab
deployment
docs
effort:L
effort:M
effort:S
frontend
plugins
qa
vs-nfd
vs-nfd:blocker
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: stwaidele/dorfteich#230
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Plan reference:
20-massnahmenplan.md-> Phase 5ADR: ADR 0019
Effort: L (3–4 AT)
Depends on: #226, #227, #228
Context
The authority's own documentation obligation runs along these building
blocks. Supplying the mapping ourselves saves them the translation work and
prevents them from guessing wrong about us.
Current state
No IT-Grundschutz material exists in the repository.
Acceptance criteria
(Verschlusssachen handling) is classified as product,
operator, or not applicable, with a one-line justification.
operator requirements say what we hand over to enable it.
document doubles as a gap list.
Out of scope
Requirements from other building blocks, and the authority's
Sicherheitskonzept.
From #201 (PR #261): the audit event catalogue at docs/architecture/audit-events.md (v1.0) is the reference for the logging/audit chapter - every emittable event id with trigger, severity, actor/target semantics and fields, plus the compatibility promise and the stdout field set. The code half is the typed union in apps/api/src/audit/audit-actions.ts; audit-catalogue.test.ts keeps document and code in step.
Done in commit
919201d(PR #277, CI run 581 green, fast-forward merged on Stefan's standing merge instruction).Evidence: docs/vs-nfd/80-grundschutz-mapping.md - every requirement of APP.3.1 and CON.11.1 classified as product/operator/n.a. with a justification; worked against the real Edition 2023 texts fetched from the BSI single PDFs (editions and retrieval date stated, dropped APP.3.1 requirements listed as such, CON.11.1 = 18 Basis requirements). Product rows point at code/config/test evidence; operator rows say what we hand over; n.a. rows are argued via the delimitation statement (no par. 52 security functions, no built-in remote maintenance). CON.11.1.A7 (marking) maps the whole of M26 incl. the answered question whether the electronic marking carries a security function (no - pinned by test). Open requirements point at their issues (M27/M28/M29/M32) so the document doubles as the gap list; the not-yet-commissioned external pentest is stated honestly.