5 Part 5: V-Modell Reference Work Products
5.3 Products
5.3.7 Requirements and Analyses
5.3.7.8 Data Protection Concept
Process module: Safety and Security (Supplier)
Responsible: Data Protection Manager (when using process module Safety and Security (Supplier))
Activity: Preparing Data Protection Concept
Participating: Security Manager
Work Product Attributes: initial
Purpose
The data protection concept regulates the implementation of legal data protection standards for the handling of personal data.
It includes statements on the following:
- Legal foundations and their implementation.
- Purpose of processing personal data.
- Origin of personal data.
- System survey and protection requirements.
- Risks.
- Requirements and measures.
Is generated by
Software Implementation, Integration and Evaluation Concept, Software Architecture (see product dependency 4.18)
Hardware Architecture, Hardware Implementation, Integration and Evaluation Concept (see product dependency 4.7)
Software Implementation, Integration and Evaluation Concept, Software Architecture (see product dependency 4.19)
Software Implementation, Integration and Evaluation Concept, Software Architecture (see product dependency 4.17)
Hardware Architecture, Hardware Implementation, Integration and Evaluation Concept (see product dependency 4.8)
Hardware Architecture, Hardware Implementation, Integration and Evaluation Concept (see product dependency 4.6)
System Implementation, Integration and Evaluation Concept, Enabling System Architecture (see product dependency 4.16)
Enabling System Implementation, Integration, and Evaluation Concept, Enabling System Architecture (see product dependency 4.24)
Enabling System Implementation, Integration, and Evaluation Concept, Enabling System Architecture (see product dependency 4.5)
Enabling System Implementation, Integration, and Evaluation Concept, Enabling System Architecture (see product dependency 4.21)
System Implementation, Integration and Evaluation Concept, System Architecture (see product dependency 4.15)
System Implementation, Integration and Evaluation Concept, System Architecture (see product dependency 4.23)
System Implementation, Integration and Evaluation Concept, System Architecture (see product dependency 4.4)
System Implementation, Integration and Evaluation Concept, System Architecture (see product dependency 4.20)
Overall System Specification (see product dependency 4.25)
Overall System Specification (see product dependency 4.26)
Depends on
Project Manual, Information Security Concept, Safety and Security Analysis (see product dependency 5.46)
Project Manual, Overall System Specification, Information Security Concept (see product dependency 5.47)
5.3.7.8.1 Legal Foundations and Their Implementation
The legal data protection provisions and regulations required for the handling of personal data shall be identified.
5.3.7.8.2 Origin and Purpose of Processing Personal Data
Origin and purpose of processing personal data shall be presented.
5.3.7.8.3 System Survey and Protection Requirements
The system survey shall focus on system elements which process personal data. The protection requirements for personal data will be specified.
5.3.7.8.4 Risks
Possible risks incurred when processing personal data shall be identified.
5.3.7.8.5 Requirements and Measures
The data protection concept shall fulfill all legal data protection requirements, e.g., legal, technical, organizational, and material requirements. In addition, the requirements must be covered completely by appropriate measures. Aspects to be covered include, but are not limited to, the following:
- Administration and processing of personal data on data carriers and servers, e.g., storage time, safekeeping, marking, re-use, destruction and deletion of programs and data no longer required.
- Physical access control/user control, access control, transfer control, input control, request control.
- Obligation to notification/consultation of the Data Protection Specialist, e.g., in case of unexpected system behavior or extraordinary events which have effects on data loss or the loss of data protection.
- Release procedures, e.g., for modified/new system elements and the transfer or personal data.
- Processing of job data, e.g., in case of installation, maintenance, repair, software maintenance and deletion/destruction of data carriers.