Zum Inhalt springen

GAP Assessment 


Domänenansatz zur Reifegrad-Bestimmung


Für ein gemeinsames Reifegrad- und Gap-Assessment empfiehlt es sich, die Controls der ISO/IEC27001: 2022 und der IEC 62443 zusammen mit den KRITIS und NIS-2 Anforderungen in übergeordnete Security Capability Domains zu gruppieren. Dadurch lassen sich Management-Anforderungen und IT/OT-Perspektiven gemeinsam bewerten. 

Security Capability Domains

D1 - Governance & ISMS

ISMS - (Nachweispflicht gem §8a BSIG)

A.5.1 Policies for Information Security, 

A.5.2 Information Security Roles and Responsibilities, 

A.5.4 Management Responsibilities, 

A.5.36 Compliance with Policies, Rules and Standards

NIS2 Art. 21 Abs. 2 a,i

IEC 62443-2-1

D2 - Asset Management

Asset-Inventar - (Nachweispflicht gem §8a BSIG)

A.5.7 Threat Intelligence, 

A.5.9 Inventory of Information and Other Associated Assets,

 A.5.12 Classification of Information, 

A.5.13 Labelling of Information, 

A.5.14 Information Transfer, 

A.5.30 ICT Readiness for Business Continuity

NIS2 Art. 21 Abs. 2 a,f

IEC 62443-2-1, IEC 62443-3-2

D3 - Risiko Management

Risikoanalyse - (Nachweispflicht gem §8a BSIG)

A.5.9 Inventory of Assets, 

A.5.10 Acceptable Use of Information and Assets, 

A.5.11 Return of Assets, 

A.5.15 Access Control, 

A.5.34 Privacy and Protection of PII

NIS2 Art. 21 Abs. 2 a

IEC 62443-3-2

D4 - Security Organisation

Organisation - (Nachweispflicht gem §8a BSIG)

A.5.3 Segregation of Duties,

 A.5.5 Contact with Authorities, 

A.5.6 Contact with Special Interest Groups

A.5.8 Information Security in Project Management

NIS2 Art. 21 Abs. 2 a,i

IEC 62443-2-1

D5 - Human Security

Personal - (Nachweispflicht gem §8a BSIG)

A.6.1 Screening, 

A.6.2 Terms and Conditions of Employment,

A.6.3 Information Security Awareness, Education and Training, 

A.6.4 Disciplinary Process, 

A.6.5 Responsibilities after Termination or Change of Employment, 

A.6.6 Confidentiality Agreements, 

A.6.7 Remote Working, 

A.6.8 Information Security Event Reporting

NIS2 Art. 21 Abs. 2 g

IEC 62443-2-1

D6 - Supplier & Third Party Security

Lieferanten - (Nachweispflicht gem §8a BSIG)

A.5.19 Information Security in Supplier Relationships, 

A.5.20 Addressing Information Security within Supplier Agreements, 

A.5.21 Managing Information Security in the ICT Supply Chain, 

A.5.22 Monitoring, Review and Change Management of Supplier Services, 

A.5.23 Information Security for Use of Cloud Services

NIS2 Art. 21 Abs. 2 d

IEC 62443-2-4

D7 - Physical Security

physische Sicherheit - (Nachweispflicht gem §8a BSIG)

Controls A.7.1–A.7.14

NIS2 Art. 21 Abs. 2 a

IEC 62443-2-1

D8 - Identity & Access Management

Zugriffsschutz - (Nachweispflicht gem §8a BSIG)

A.5.15 Access Control, 

A.5.16 Identity Management, 

A.5.17 Authentication Information, 

A.5.18 Access Rights, 

A.8.2 Privileged Access Rights, 

A.8.3 Information Access Restriction, 

A.8.5 Secure Authentication

NIS2 Art. 21 Abs. 2 j

IEC 62443-3-3 FR1 – Identification & Authentication Control

IEC 62443-3-3 FR2 – Use Control

D9 - Network Security

Netzwerksicherheit - (Nachweispflicht gem §8a BSIG)

A.8.20 Network Security, 

A.8.21 Security of Network Services, 

A.8.22 Segregation of Networks, 

A.8.24 Use of Cryptography, 

A.8.25 Secure Development Lifecycle (Netzwerkaspekte), 

A.8.26 Application Security Requirements

NIS2 Art. 21 Abs. 2 f, j

IEC 62443-3-2

IEC 62443-3-3 FR4 - Data Confidentiality

IEC 62443-3-3 FR5 - Restricted Data Flow

D10 - Endpoint & System Security

Systemhärtung - (Nachweispflicht gem §8a BSIG)

A.8.1 User Endpoint Devices,

 A.8.7 Protection Against Malware, 

A.8.8 Management of Technical Vulnerabilities, A.8.9 Configuration Management, 

A.8.10 Information Deletion, 

A.8.11 Data Masking, A.8.12 Data Leakage Prevention, 

A.8.13 Information Backup

 NIS2 Art. 21 Abs. 2 f

IEC 62443-3-3FR3 - System Integrity

IEC 62443-3-3FR7 - Resource Availability

D11 - Secure Engineering & Change Management

Änderungsmanagement - (Nachweispflicht gem §8a BSIG)

A.8.25 Secure Development Lifecycle, 

A.8.26 Application Security Requirements, 

A.8.27 Secure System Architecture and Engineering Principles, 

A.8.28 Secure Coding,

 A.8.29 Security Testing in Development and Acceptance, 

A.8.30 Outsourced Development, 

A.8.31 Separation of Development, Test and Production Environments, 

A.8.32 Change Management

NIS2 Art. 21 Abs. 2 b, e

IEC 62443-4-1

IEC 62443-3-3 FR4 - Data Confidentiality

D12 - Vulnerability & Patch Management

Schwachstellenmanagement - (Nachweispflicht gem §8a BSIG)

A.8.8 Management of Technical Vulnerabilities, 

A.8.9 Configuration Management, 

A.8.32 Change Management

NIS2 Art. 21 Abs. 2 c

IEC 62443-2-3, IEC 62443-4-1

D13 - Monitoring, Detection & Incident Response

Angriffserkennung - (Nachweispflicht gem §8a BSIG)

A.5.24 Information Security Incident Management Planning and Preparation,

A.5.25 Assessment and Decision on Information Security Events, 

A.5.26 Response to Information Security Incidents, 

A.5.27 Learning from Information Security Incidents, 

A.5.28 Collection of Evidence, 

A.8.15 Logging, A.8.16 Monitoring Activities, 

A.8.17 Clock Synchronization 

NIS2 Art. 21 Abs. 2 b

IEC 62443-2-1

IEC 62443-3-3 FR6 - Timely Response to Events

D14 - Backup, Recovery & Operational Resilience

BCM - (Nachweispflicht gem §8a BSIG)

A.8.13 Information Backup,

 A.5.29 Information Security During Disruption, 

A.5.30 ICT Readiness for Business Continuity

NIS2 Art. 21 Abs. 2 b,h

IEC 62443-2-1,

IEC 62443-3-3 FR7 - Resource Availability

D15 - Compliance, Audit & Continuous Improvement

Auditnachweise - (Nachweispflicht gem §8a BSIG)

A.5.31 Legal, Statutory, Regulatory and Contractual Requirements, 

A.5.32 Intellectual Property Rights, 

A.5.33 Protection of Records,

 A.5.34 Privacy and Protection of PII, 

A.5.35 Independent Review of Information Security, 

A.5.36 Compliance with Policies, Rules and Standards, 

A.5.37 Documented Operating Procedures

NIS2 Art. 21 Abs. 2 a,i

IEC 62443-2-1

Jede Domäne wird anhand derselben Bewertungsdimensionen beurteilt:

  • Governance (Verantwortlichkeiten und Richtlinien)
  • Prozesse (Dokumentation und Standardisierung)
  • Technische Umsetzung (Implementierung der Maßnahmen)
  • Wirksamkeit (Messung, KPIs, Audits)
  • Kontinuierliche Verbesserung (Lessons Learned, Optimierung)

Reifegrad-Bewertung:

  • 0 ​ - nicht vorhanden
  • 1  - adhoc
  • 2  - wiederholbar
  • 3  - definiert & eingeführt
  • 4  - gesteuert & gemessen
  • 5  - kontinuierlich optimiert