<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Cenedril Wiki</title><description>Updates from the Cenedril ISMS wiki — policies, registers, controls, threats and regulations.</description><link>https://cenedril.net/</link><language>de-DE</language><item><title>BAIT &amp; VAIT — BaFin-Anforderungen an die IT von Banken und Versicherern</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>BAIT, VAIT und KAIT: Aufbau, Anwendungsbereich, Prüfungspraxis der BaFin und Mapping zu ISO 27001 und DORA.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>BDSG — Bundesdatenschutzgesetz</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Deutsches Bundesdatenschutzgesetz: Geltungsbereich, nationale Konkretisierungen zur DSGVO und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.34</category><category>A.5.13</category><category>A.5.14</category><category>A.5.24</category><category>A.5.32</category><category>A.5.36</category><category>A.6.3</category><category>A.6.6</category><category>A.7.10</category><category>A.8.10</category><category>A.8.11</category><category>A.8.24</category></item><item><title>BSI C5 — Cloud Computing Compliance Criteria Catalogue</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>BSI C5: Sicherheits-Anforderungen für Cloud-Dienste, Typ-1- und Typ-2-Testate, Zusammenspiel mit ISO 27001 und SOC 2.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>BSI IT-Grundschutz — Standards 200-x und Kompendium</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>BSI IT-Grundschutz: Standards 200-1/200-2/200-3, IT-Grundschutz-Kompendium, Zertifizierung und Verhältnis zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>BSIG — Gesetz über das Bundesamt für Sicherheit in der Informationstechnik</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Das BSIG: Aufgaben des BSI, KRITIS-Pflichten, Meldepflichten und Mapping zu ISO 27001 für Betreiber kritischer Infrastrukturen.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.27</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.5.37</category><category>A.6.3</category><category>A.8.7</category><category>A.8.8</category><category>A.8.16</category></item><item><title>CIS Controls — 18 priorisierte Sicherheitskontrollen</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>CIS Controls v8.1: 18 Controls, drei Implementation Groups (IG1/IG2/IG3) und Mapping zu ISO 27001 und NIST CSF.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>Cyber Resilience Act — CRA</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>EU-Verordnung für Cybersicherheit von Produkten mit digitalen Elementen: Geltungsbereich, Pflichten, CE-Kennzeichnung und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.8</category><category>A.5.21</category><category>A.5.24</category><category>A.5.37</category><category>A.6.3</category><category>A.8.8</category><category>A.8.9</category><category>A.8.25</category><category>A.8.26</category><category>A.8.27</category><category>A.8.28</category><category>A.8.29</category><category>A.8.30</category></item><item><title>DORA — Digital Operational Resilience Act</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>EU-Verordnung zur digitalen operationellen Resilienz im Finanzsektor: Anforderungen, IKT-Risikomanagement, Drittparteien und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.19</category><category>A.5.20</category><category>A.5.21</category><category>A.5.22</category><category>A.5.23</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.27</category><category>A.5.29</category><category>A.5.30</category><category>A.8.6</category><category>A.8.8</category><category>A.8.14</category><category>A.8.15</category><category>A.8.16</category></item><item><title>DSG — Bundesgesetz über den Datenschutz (Schweiz)</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Revidiertes Schweizer Datenschutzgesetz: Geltungsbereich, Anforderungen an Informationssicherheit und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.34</category><category>A.5.13</category><category>A.5.14</category><category>A.5.24</category><category>A.5.32</category><category>A.5.36</category><category>A.6.3</category><category>A.7.10</category><category>A.8.10</category><category>A.8.11</category><category>A.8.24</category><category>A.8.25</category></item><item><title>DSGVO — Datenschutz-Grundverordnung</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>EU-Datenschutz-Grundverordnung: Geltungsbereich, Anforderungen an Informationssicherheit und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.34</category><category>A.5.13</category><category>A.5.14</category><category>A.5.15</category><category>A.5.24</category><category>A.5.32</category><category>A.5.33</category><category>A.5.36</category><category>A.6.3</category><category>A.6.5</category><category>A.7.10</category><category>A.8.10</category><category>A.8.11</category><category>A.8.12</category><category>A.8.24</category><category>A.8.25</category></item><item><title>BAIT &amp; VAIT — BaFin IT Requirements for Banks and Insurers</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>BAIT, VAIT and KAIT: structure, scope, BaFin audit practice and mapping to ISO 27001 and DORA.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>BDSG — German Federal Data Protection Act</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>German Federal Data Protection Act: scope, national specifications to the GDPR and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.34</category><category>A.5.13</category><category>A.5.14</category><category>A.5.24</category><category>A.5.32</category><category>A.5.36</category><category>A.6.3</category><category>A.6.6</category><category>A.7.10</category><category>A.8.10</category><category>A.8.11</category><category>A.8.24</category></item><item><title>BSI C5 — Cloud Computing Compliance Criteria Catalogue</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>BSI C5: security requirements for cloud services, Type 1 and Type 2 attestations, interplay with ISO 27001 and SOC 2.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>BSI IT-Grundschutz — 200-x Standards and Compendium</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>BSI IT-Grundschutz: Standards 200-1/200-2/200-3, the IT-Grundschutz Compendium, certification and relationship to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>BSIG — Act on the German Federal Office for Information Security</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>The BSIG: tasks of the BSI, KRITIS obligations, reporting duties and mapping to ISO 27001 for operators of critical infrastructure.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.27</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.5.37</category><category>A.6.3</category><category>A.8.7</category><category>A.8.8</category><category>A.8.16</category></item><item><title>CIS Controls — 18 prioritised security controls</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>CIS Controls v8.1: 18 Controls, three Implementation Groups (IG1/IG2/IG3) and mapping to ISO 27001 and NIST CSF.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>Cyber Resilience Act — CRA</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>EU regulation on cybersecurity for products with digital elements: scope, obligations, CE marking and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.8</category><category>A.5.21</category><category>A.5.24</category><category>A.5.37</category><category>A.6.3</category><category>A.8.8</category><category>A.8.9</category><category>A.8.25</category><category>A.8.26</category><category>A.8.27</category><category>A.8.28</category><category>A.8.29</category><category>A.8.30</category></item><item><title>DORA — Digital Operational Resilience Act</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>EU regulation on digital operational resilience in the financial sector: requirements, ICT risk management, third parties and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.19</category><category>A.5.20</category><category>A.5.21</category><category>A.5.22</category><category>A.5.23</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.27</category><category>A.5.29</category><category>A.5.30</category><category>A.8.6</category><category>A.8.8</category><category>A.8.14</category><category>A.8.15</category><category>A.8.16</category></item><item><title>FADP — Swiss Federal Act on Data Protection</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Revised Swiss Federal Act on Data Protection: scope, information security requirements and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.34</category><category>A.5.13</category><category>A.5.14</category><category>A.5.24</category><category>A.5.32</category><category>A.5.36</category><category>A.6.3</category><category>A.7.10</category><category>A.8.10</category><category>A.8.11</category><category>A.8.24</category><category>A.8.25</category></item><item><title>GDPR — General Data Protection Regulation</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>EU General Data Protection Regulation: scope, information security requirements and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.34</category><category>A.5.13</category><category>A.5.14</category><category>A.5.15</category><category>A.5.24</category><category>A.5.32</category><category>A.5.33</category><category>A.5.36</category><category>A.6.3</category><category>A.6.5</category><category>A.7.10</category><category>A.8.10</category><category>A.8.11</category><category>A.8.12</category><category>A.8.24</category><category>A.8.25</category></item><item><title>FINMA Circular — Operational Risks (Switzerland)</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>FINMA Circular 2023/1 on operational risks and resilience: scope, ICT requirements and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.19</category><category>A.5.20</category><category>A.5.21</category><category>A.5.22</category><category>A.5.23</category><category>A.5.24</category><category>A.5.25</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.8.6</category><category>A.8.8</category><category>A.8.14</category><category>A.8.15</category><category>A.8.16</category></item><item><title>GeschGehG — Trade Secrets Act</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>German Act on the Protection of Trade Secrets: reasonable confidentiality measures, reverse engineering and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.10</category><category>A.5.11</category><category>A.5.12</category><category>A.5.13</category><category>A.5.14</category><category>A.5.15</category><category>A.5.18</category><category>A.5.19</category><category>A.5.20</category><category>A.5.32</category><category>A.6.2</category><category>A.6.3</category><category>A.6.5</category><category>A.6.6</category><category>A.8.10</category><category>A.8.11</category><category>A.8.12</category><category>A.8.24</category></item><item><title>HGB &amp; AO — German Commercial Code and Tax Code</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Bookkeeping duties, retention periods and audit-proof records under HGB and AO: information security requirements and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.10</category><category>A.5.13</category><category>A.5.33</category><category>A.5.36</category><category>A.5.37</category><category>A.6.3</category><category>A.8.4</category><category>A.8.10</category><category>A.8.13</category><category>A.8.14</category><category>A.8.15</category><category>A.8.16</category><category>A.8.24</category><category>A.8.34</category></item><item><title>ISG — Swiss Information Security Act</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Swiss Information Security Act: scope, cyber-reporting duty for critical infrastructure operators and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.27</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.6.3</category><category>A.8.7</category><category>A.8.8</category><category>A.8.16</category></item><item><title>ISO 22301 — Business Continuity Management</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>ISO 22301:2019: requirements for a business continuity management system (BCMS), certification and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>ISO/IEC 27001 — Information Security Management System</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>ISO 27001: structure, requirements, certification and mapping to BSI IT-Grundschutz, NIST CSF and related standards.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>ISO/IEC 27002 — Information Security Controls Guidance</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>ISO 27002:2022: implementation guidance for the 93 Annex A controls, new structure, attributes and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>ISO/IEC 27005 — Information Security Risk Management</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>ISO 27005:2022: methodology for risk identification, analysis, evaluation and treatment in an ISO 27001 ISMS.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>IT-Sicherheitsgesetz 2.0 (Germany)</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>IT-SiG 2.0: extension of the BSIG, duties for KRITIS operators and companies in special public interest, mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.19</category><category>A.5.20</category><category>A.5.21</category><category>A.5.23</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.30</category><category>A.5.36</category><category>A.8.7</category><category>A.8.8</category><category>A.8.16</category></item><item><title>KonTraG — Act on Control and Transparency in Business</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Risk management obligations for stock corporations under KonTraG: early-warning system, internal control system and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.1</category><category>A.5.2</category><category>A.5.4</category><category>A.5.7</category><category>A.5.24</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.6.3</category><category>A.8.8</category><category>A.8.16</category></item><item><title>NIS2 Directive — EU Cybersecurity Directive</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>The EU NIS2 Directive: scope for essential and important entities, obligations and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.4</category><category>A.5.7</category><category>A.5.19</category><category>A.5.20</category><category>A.5.21</category><category>A.5.23</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.6.3</category><category>A.8.7</category><category>A.8.8</category><category>A.8.16</category></item><item><title>NIST Cybersecurity Framework — Govern, Identify, Protect, Detect, Respond, Recover</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>NIST CSF 2.0: six functions, four Implementation Tiers, the Profile concept and mapping to ISO 27001 and CIS Controls.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>TISAX — Trusted Information Security Assessment Exchange</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>TISAX label for the automotive industry: ISA catalogue, maturity levels AL1/AL2/AL3, protection classes and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>TTDSG — Telecommunications Telemedia Data Protection Act</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>German law on cookies, tracking and terminal-device access: scope, consent requirements and mapping to ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.13</category><category>A.5.14</category><category>A.5.34</category><category>A.5.36</category><category>A.6.3</category><category>A.8.10</category><category>A.8.11</category><category>A.8.24</category></item><item><title>FINMA-Rundschreiben (Schweiz) — Operationelle Risiken</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>FINMA-Rundschreiben 2023/1 zu operationellen Risiken und Resilienz: Geltungsbereich, IKT-Anforderungen und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.19</category><category>A.5.20</category><category>A.5.21</category><category>A.5.22</category><category>A.5.23</category><category>A.5.24</category><category>A.5.25</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.8.6</category><category>A.8.8</category><category>A.8.14</category><category>A.8.15</category><category>A.8.16</category></item><item><title>GeschGehG — Geschäftsgeheimnisgesetz</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Deutsches Gesetz zum Schutz von Geschäftsgeheimnissen: angemessene Geheimhaltungsmaßnahmen, Reverse Engineering und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.10</category><category>A.5.11</category><category>A.5.12</category><category>A.5.13</category><category>A.5.14</category><category>A.5.15</category><category>A.5.18</category><category>A.5.19</category><category>A.5.20</category><category>A.5.32</category><category>A.6.2</category><category>A.6.3</category><category>A.6.5</category><category>A.6.6</category><category>A.8.10</category><category>A.8.11</category><category>A.8.12</category><category>A.8.24</category></item><item><title>HGB &amp; AO — Handelsgesetzbuch und Abgabenordnung</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Buchführungspflichten, Aufbewahrungsfristen und Revisionssicherheit nach HGB und AO: Anforderungen an die Informationssicherheit und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.10</category><category>A.5.13</category><category>A.5.33</category><category>A.5.36</category><category>A.5.37</category><category>A.6.3</category><category>A.8.4</category><category>A.8.10</category><category>A.8.13</category><category>A.8.14</category><category>A.8.15</category><category>A.8.16</category><category>A.8.24</category><category>A.8.34</category></item><item><title>ISG — Informationssicherheitsgesetz (Schweiz)</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Schweizer Informationssicherheitsgesetz: Geltungsbereich, Cyber-Meldepflicht für kritische Infrastrukturen und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.27</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.6.3</category><category>A.8.7</category><category>A.8.8</category><category>A.8.16</category></item><item><title>ISO 22301 — Business-Continuity-Management</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>ISO 22301:2019: Anforderungen an ein Business-Continuity-Management-System (BCMS), Zertifizierung und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>ISO/IEC 27001 — Informationssicherheits-Managementsystem</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>ISO 27001: Aufbau, Anforderungen, Zertifizierung und Mapping zu BSI-Grundschutz, NIST CSF und weiteren Standards.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>ISO/IEC 27002 — Leitfaden für Informationssicherheits-Kontrollen</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>ISO 27002:2022: Umsetzungs-Leitfaden zu den 93 Annex-A-Kontrollen, neue Struktur, Attribute und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>ISO/IEC 27005 — Informationssicherheits-Risikomanagement</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>ISO 27005:2022: Methodik für Risikoidentifikation, -analyse, -bewertung und -behandlung im ISMS nach ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>IT-Sicherheitsgesetz 2.0 (Deutschland)</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Das IT-SiG 2.0: Erweiterung des BSIG, Pflichten für KRITIS und Unternehmen im besonderen öffentlichen Interesse, Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.7</category><category>A.5.19</category><category>A.5.20</category><category>A.5.21</category><category>A.5.23</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.30</category><category>A.5.36</category><category>A.8.7</category><category>A.8.8</category><category>A.8.16</category></item><item><title>KonTraG — Gesetz zur Kontrolle und Transparenz im Unternehmensbereich</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Risikomanagement-Pflichten für Aktiengesellschaften nach KonTraG: Frühwarnsystem, internes Kontrollsystem und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.1</category><category>A.5.2</category><category>A.5.4</category><category>A.5.7</category><category>A.5.24</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.6.3</category><category>A.8.8</category><category>A.8.16</category></item><item><title>NIS2-Richtlinie — EU-Cybersicherheitsrichtlinie</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Die NIS2-Richtlinie der EU: Geltungsbereich für wichtige und besonders wichtige Einrichtungen, Pflichten und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.4</category><category>A.5.7</category><category>A.5.19</category><category>A.5.20</category><category>A.5.21</category><category>A.5.23</category><category>A.5.24</category><category>A.5.25</category><category>A.5.26</category><category>A.5.29</category><category>A.5.30</category><category>A.5.36</category><category>A.6.3</category><category>A.8.7</category><category>A.8.8</category><category>A.8.16</category></item><item><title>NIST Cybersecurity Framework — Govern, Identify, Protect, Detect, Respond, Recover</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>NIST CSF 2.0: sechs Funktionen, vier Implementation Tiers, Profile-Konzept und Mapping zu ISO 27001 und CIS Controls.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>TISAX — Trusted Information Security Assessment Exchange</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>TISAX-Prüfsiegel für die Automobilindustrie: ISA-Katalog, Reifegrade AL1/AL2/AL3, Schutzklassen und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category></item><item><title>TTDSG — Telekommunikation-Telemedien-Datenschutzgesetz</title><link>https://cenedril.net/wiki/en/gesetze-und-standards/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/gesetze-und-standards/</guid><description>Deutsches Gesetz zu Cookies, Tracking und Endgeräte-Zugriff: Geltungsbereich, Einwilligungspflichten und Mapping zu ISO 27001.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate><category>gesetze-und-standards</category><category>A.5.13</category><category>A.5.14</category><category>A.5.34</category><category>A.5.36</category><category>A.6.3</category><category>A.8.10</category><category>A.8.11</category><category>A.8.24</category></item><item><title>A.5.1 — Richtlinien für Informationssicherheit</title><link>https://cenedril.net/wiki/en/kontrollen/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/kontrollen/</guid><description>ISO 27001 Control A.5.1: Richtlinien erstellen, freigeben und kommunizieren. Umsetzung, Audit-Nachweise, KPI.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>kontrollen</category><category>A.5.1</category></item><item><title>A.5.10 — Akzeptable Nutzung von Informationswerten</title><link>https://cenedril.net/wiki/en/kontrollen/</link><guid isPermaLink="true">https://cenedril.net/wiki/en/kontrollen/</guid><description>ISO 27001 Control A.5.10: Nutzungsregeln für Informationen und Assets definieren. Umsetzung, Audit-Nachweise, KPI.</description><pubDate>Fri, 17 Apr 2026 00:00:00 GMT</pubDate><category>kontrollen</category><category>A.5.10</category></item></channel></rss>