GAP Assessment
Domänenansatz zur Reifegrad-Bestimmung
Für ein gemeinsames Reifegrad- und Gap-Assessment empfiehlt es sich, die Controls der ISO/IEC27001: 2022 und der IEC 62443 zusammen mit den KRITIS und NIS-2 Anforderungen in übergeordnete Security Capability Domains zu gruppieren. Dadurch lassen sich Management-Anforderungen und IT/OT-Perspektiven gemeinsam bewerten.
Security Capability Domains
D1 - Governance & ISMS ISMS - (Nachweispflicht gem §8a BSIG) | A.5.1 Policies for Information Security, A.5.2 Information Security Roles and Responsibilities, A.5.4 Management Responsibilities, A.5.36 Compliance with Policies, Rules and Standards NIS2 Art. 21 Abs. 2 a,i IEC 62443-2-1 |
D2 - Asset Management Asset-Inventar - (Nachweispflicht gem §8a BSIG) | A.5.7 Threat Intelligence, A.5.9 Inventory of Information and Other Associated Assets, A.5.12 Classification of Information, A.5.13 Labelling of Information, A.5.14 Information Transfer, A.5.30 ICT Readiness for Business Continuity NIS2 Art. 21 Abs. 2 a,f IEC 62443-2-1, IEC 62443-3-2 |
D3 - Risiko Management Risikoanalyse - (Nachweispflicht gem §8a BSIG) | A.5.9 Inventory of Assets, A.5.10 Acceptable Use of Information and Assets, A.5.11 Return of Assets, A.5.15 Access Control, A.5.34 Privacy and Protection of PII NIS2 Art. 21 Abs. 2 a IEC 62443-3-2 |
D4 - Security Organisation Organisation - (Nachweispflicht gem §8a BSIG) | A.5.3 Segregation of Duties, A.5.5 Contact with Authorities, A.5.6 Contact with Special Interest Groups A.5.8 Information Security in Project Management NIS2 Art. 21 Abs. 2 a,i IEC 62443-2-1 |
D5 - Human Security Personal - (Nachweispflicht gem §8a BSIG) | A.6.1 Screening, A.6.2 Terms and Conditions of Employment, A.6.3 Information Security Awareness, Education and Training, A.6.4 Disciplinary Process, A.6.5 Responsibilities after Termination or Change of Employment, A.6.6 Confidentiality Agreements, A.6.7 Remote Working, A.6.8 Information Security Event Reporting NIS2 Art. 21 Abs. 2 g IEC 62443-2-1 |
D6 - Supplier & Third Party Security Lieferanten - (Nachweispflicht gem §8a BSIG) | A.5.19 Information Security in Supplier Relationships, A.5.20 Addressing Information Security within Supplier Agreements, A.5.21 Managing Information Security in the ICT Supply Chain, A.5.22 Monitoring, Review and Change Management of Supplier Services, A.5.23 Information Security for Use of Cloud Services NIS2 Art. 21 Abs. 2 d IEC 62443-2-4 |
D7 - Physical Security physische Sicherheit - (Nachweispflicht gem §8a BSIG) | Controls A.7.1–A.7.14 NIS2 Art. 21 Abs. 2 a IEC 62443-2-1 |
D8 - Identity & Access Management Zugriffsschutz - (Nachweispflicht gem §8a BSIG) | A.5.15 Access Control, A.5.16 Identity Management, A.5.17 Authentication Information, A.5.18 Access Rights, A.8.2 Privileged Access Rights, A.8.3 Information Access Restriction, A.8.5 Secure Authentication NIS2 Art. 21 Abs. 2 j IEC 62443-3-3 FR1 – Identification & Authentication Control IEC 62443-3-3 FR2 – Use Control |
D9 - Network Security Netzwerksicherheit - (Nachweispflicht gem §8a BSIG) | A.8.20 Network Security, A.8.21 Security of Network Services, A.8.22 Segregation of Networks, A.8.24 Use of Cryptography, A.8.25 Secure Development Lifecycle (Netzwerkaspekte), A.8.26 Application Security Requirements NIS2 Art. 21 Abs. 2 f, j IEC 62443-3-2 IEC 62443-3-3 FR4 - Data Confidentiality IEC 62443-3-3 FR5 - Restricted Data Flow |
D10 - Endpoint & System Security Systemhärtung - (Nachweispflicht gem §8a BSIG) | A.8.1 User Endpoint Devices, A.8.7 Protection Against Malware, A.8.8 Management of Technical Vulnerabilities, A.8.9 Configuration Management, A.8.10 Information Deletion, A.8.11 Data Masking, A.8.12 Data Leakage Prevention, A.8.13 Information Backup NIS2 Art. 21 Abs. 2 f IEC 62443-3-3FR3 - System Integrity IEC 62443-3-3FR7 - Resource Availability |
D11 - Secure Engineering & Change Management Änderungsmanagement - (Nachweispflicht gem §8a BSIG) | A.8.25 Secure Development Lifecycle, A.8.26 Application Security Requirements, A.8.27 Secure System Architecture and Engineering Principles, A.8.28 Secure Coding, A.8.29 Security Testing in Development and Acceptance, A.8.30 Outsourced Development, A.8.31 Separation of Development, Test and Production Environments, A.8.32 Change Management NIS2 Art. 21 Abs. 2 b, e IEC 62443-4-1 IEC 62443-3-3 FR4 - Data Confidentiality |
D12 - Vulnerability & Patch Management Schwachstellenmanagement - (Nachweispflicht gem §8a BSIG) | A.8.8 Management of Technical Vulnerabilities, A.8.9 Configuration Management, A.8.32 Change Management NIS2 Art. 21 Abs. 2 c IEC 62443-2-3, IEC 62443-4-1 |
D13 - Monitoring, Detection & Incident Response Angriffserkennung - (Nachweispflicht gem §8a BSIG) | A.5.24 Information Security Incident Management Planning and Preparation, A.5.25 Assessment and Decision on Information Security Events, A.5.26 Response to Information Security Incidents, A.5.27 Learning from Information Security Incidents, A.5.28 Collection of Evidence, A.8.15 Logging, A.8.16 Monitoring Activities, A.8.17 Clock Synchronization NIS2 Art. 21 Abs. 2 b IEC 62443-2-1 IEC 62443-3-3 FR6 - Timely Response to Events |
D14 - Backup, Recovery & Operational Resilience BCM - (Nachweispflicht gem §8a BSIG) | A.8.13 Information Backup, A.5.29 Information Security During Disruption, A.5.30 ICT Readiness for Business Continuity NIS2 Art. 21 Abs. 2 b,h IEC 62443-2-1, IEC 62443-3-3 FR7 - Resource Availability |
D15 - Compliance, Audit & Continuous Improvement Auditnachweise - (Nachweispflicht gem §8a BSIG) | A.5.31 Legal, Statutory, Regulatory and Contractual Requirements, A.5.32 Intellectual Property Rights, A.5.33 Protection of Records, A.5.34 Privacy and Protection of PII, A.5.35 Independent Review of Information Security, A.5.36 Compliance with Policies, Rules and Standards, A.5.37 Documented Operating Procedures NIS2 Art. 21 Abs. 2 a,i IEC 62443-2-1 |
Jede Domäne wird anhand derselben Bewertungsdimensionen beurteilt:
- Governance (Verantwortlichkeiten und Richtlinien)
- Prozesse (Dokumentation und Standardisierung)
- Technische Umsetzung (Implementierung der Maßnahmen)
- Wirksamkeit (Messung, KPIs, Audits)
- Kontinuierliche Verbesserung (Lessons Learned, Optimierung)
Reifegrad-Bewertung:
- 0 - nicht vorhanden
- 1 - adhoc
- 2 - wiederholbar
- 3 - definiert & eingeführt
- 4 - gesteuert & gemessen
- 5 - kontinuierlich optimiert