{
  "bam_id": "NIS2-021e-PATCH",
  "regulation": "NIS-2",
  "article": "Art. 21 §2e",
  "status": "ausstehend",
  "tags": [
    "patch",
    "schwachstellen",
    "vulnerability"
  ],
  "cross_refs": [
    "CRA Anh. I §2a",
    "ISO 27001 A.12.6.1"
  ],
  "requirement": {
    "text": "Sicherheit beim Erwerb, Entwicklung und Wartung von Netz- und Informationssystemen – einschließlich Umgang mit Schwachstellen und deren Offenlegung.",
    "source": "NIS-2 Art. 21 §2e",
    "priority": "hoch"
  },
  "gap_check": {
    "question": "Existiert ein dokumentierter Patch-Management-Prozess mit definierten SLAs für kritische Schwachstellen (z.B. CVSS ≥ 9: 24h, CVSS ≥ 7: 72h)?",
    "if_yes": "SLAs und Ausnahmen dokumentieren und regelmäßig messen.",
    "if_no": "Kein strukturiertes Patch-Management – kritisches Sicherheitsrisiko.",
    "if_partial": "Prozess vorhanden aber keine messbaren SLAs oder Ausnahmeregelungen."
  },
  "remediation": {
    "summary": "Strukturiertes Patch-Management mit SLAs einführen",
    "steps": [
      "Vulnerability-Scanner einsetzen (Qualys, Nessus, OpenVAS)",
      "SLAs definieren: CVSS ≥ 9 → 24h, CVSS ≥ 7 → 72h, CVSS ≥ 4 → 7 Tage",
      "Ausnahmeprozess für nicht patchbare Systeme mit Workarounds dokumentieren",
      "Monatliches Patch-Reporting an Leitungsebene"
    ],
    "effort": "mittel",
    "deadline": "kurzfristig",
    "tools": [
      "Vulnerability-Scanner",
      "Patch-Management-Tool",
      "SLA-Tracking"
    ],
    "book_reference": {
      "book": "NIS-2 Survival Kit",
      "chapter": "Kap. 8 – Patch- und Schwachstellenmanagement"
    },
    "cost_estimate": {
      "pt_min": 4,
      "pt_max": 8,
      "note": "Prozess + Scanner-Einrichtung"
    }
  },
  "risk": {
    "likelihood": 4,
    "impact": 4,
    "score": 8,
    "description": "Ungepatchte Schwachstellen sind häufigste Angriffsvektoren bei Ransomware.",
    "regulatory_fine": {
      "max_eur": 10000000,
      "max_pct": "2% Jahresumsatz",
      "basis": "NIS-2 Art. 34 – je nachdem was höher ist"
    }
  },
  "control": {
    "measure": "Automatisiertes Patch-Management mit CVSS-basierten SLAs und monatlichem Reporting",
    "priority": "sofort",
    "type": "technisch"
  },
  "evidence": {
    "type": "Patch-Policy + SLA-Tracking + Scan-Reports",
    "template": "Patch-Management-Policy",
    "audit_ready": true
  },
  "iso27001_mapping": {
    "controls": [
      "A.12.6.1",
      "A.14.2.3"
    ],
    "coverage": "vollständig"
  },
  "iso27001_2022_controls": [
    "7.13",
    "8.1",
    "8.19",
    "8.25",
    "8.32",
    "8.7",
    "8.8"
  ],
  "_bam_uri": "https://bam.brain-media.de/id/NIS2-021e-PATCH",
  "_model_version": "2.0",
  "_service": "Compliance Trace",
  "_license": "CC BY-SA 4.0 (see LICENSE-DATA)",
  "_attribution": "Brain-Media Audit Model (BAM), Dr. Holger Reibold, brain-media.de"
}