Änderungsprotokoll

Was wir als fehlend benannt haben, und wann es das nicht mehr war.

Wir veröffentlichen ein Register Abschnitt für Abschnitt, wo jede Anforderung eines ISO-Managementsystems im Produkt liegt, einschließlich der Teile, die noch nicht gebaut waren. Dies ist die Aufzeichnung, wie diese Eingeständnisse geschlossen wurden. 40 davon, jedes genau so zitiert, wie es veröffentlicht wurde.

Aus den Registern selbst erzeugt, nicht nachträglich geschrieben. Eine Lücke kommt auf diese Seite, indem sie zuerst auf der Abdeckungsseite stand, und nur deshalb lohnt sich das Lesen.

Die Zitate sind auf Englisch, der Sprache, in der sie veröffentlicht wurden. Ein übersetztes Zitat wäre nicht mehr der Satz, den wir veröffentlicht haben.

28. August 2026

  • 8.6Freigabe von Produkten und Dienstleistungen gegen die geplanten VorkehrungenISO 9001

    War: No release records and no evidence of conformity to acceptance criteria, nor of the person authorising release.

22. August 2026

  • 6.2Qualitätsziele, messbar, überwacht und geplantISO 9001

    War: The machinery is right and the labelling is not: objectives are measurable, monitored and evidenced, but they are stored and presented as security objectives. 9001 6.2.1 asks for quality objectives at relevant functions and levels, and an auditor reads the screen. 6.2.2 also asks what will be done, with what resources, by whom, when, and how results are evaluated, and only the last of those is captured.

  • 7.1.6Das Wissen, das die Organisation braucht, gepflegt und verfügbarISO 9001

    War: Organizational knowledge is a 9001-only clause with no 27001 counterpart. Documents can hold the knowledge itself, but there is no way to mark a document as organizational knowledge, give it an owner, or review it for currency, so nothing answers 7.1.6 as a clause.

13. August 2026

  • 7.1.5Ressourcen zur Überwachung und Messung und ihre RückführbarkeitISO 9001

    War: No calibration records, no equipment identification, no measurement traceability to international or national standards. For a manufacturer this is a routine audit finding and there is nothing here to answer it with. For a pure service company it is often not applicable, but that determination itself has to be recorded and cannot be.

  • 9.1.2Kundenzufriedenheit, als Wahrnehmung überwachtISO 9001

    War: A 9001-only clause with nothing behind it. It asks the organization to monitor customers' perception of the degree to which their needs have been met, and to determine the methods for obtaining and reviewing that information.

4. August 2026

  • 6.1.2Wie Risiko beurteilt wird, auf der eigenen SkalaISO/IEC 27001

    War: Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. The assessment event itself is now recorded (8.2).

  • 6.1.2Wie KI-Risiko beurteilt wird, samt Schaden über die Organisation hinausISO/IEC 42001

    War: Criteria are prose the system cannot evaluate against, and likelihood and impact are fixed 1–5 so an organization cannot use its own scale. 42001 additionally asks that the criteria account for consequences to individuals and to society, not only to the organization, and the register has no field that separates them.

3. August 2026

  • 4.1Die Organisation und ihr Umfeld verstehenISO/IEC 27001

    War: Issues are captured as text. Nothing links an issue to the risk or objective it drives, and there is no review cadence.

  • 4.2Wer ein Interesse hat und was er verlangtISO/IEC 27001

    War: One free-text field conflates needs with requirements, and there is no field for which requirements the ISMS will address (4.2 c).

  • 4.3Festlegen, was das ISMS abdecktISO/IEC 27001

    War: The scope statement is an unversioned, unapproved column outside the document module, and has no field for interfaces and dependencies (4.3 c).

  • 5.2Eine InformationssicherheitsrichtlinieISO/IEC 27001

    War: Versioning and approval are strong. No flag identifies which document is *the* policy, and there is no record of it being communicated or made available (5.2 f, g).

  • 6.1.3Maßnahmen auswählen und angeben, welche geltenISO/IEC 27001

    War: The SoA renders and hashes server-side. There is no Annex A catalogue in the database, so the 6.1.3 c) check that no necessary control was omitted cannot be performed by the system.

  • 6.2Sicherheitsziele und wie sie erreicht werdenISO/IEC 27001

    War: Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated (6.2 e–i).

  • 7.3Menschen bewusst machen, worum es gehtISO/IEC 27001

    War: Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.

  • 7.5Dokumentierte Information lenkenISO/IEC 27001

    War: Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.

  • 8.1Den Betrieb des ISMS planen und steuernISO/IEC 27001

    War: Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes.

  • 8.2Risiko in geplanten Abständen und bei Änderungen beurteilenISO/IEC 27001

    War: Assessments are recorded as events with retained results, and the interval is planned rather than inferred. But a change-triggered assessment is one someone remembered to raise, and nothing in the product detects that a significant change occurred.

  • 8.3Den Risikobehandlungsplan umsetzenISO/IEC 27001

    War: Per-risk treatment plan and status. No record of the results of implementation, which 8.3 requires be retained.

  • 9.1Überwachen, messen, analysieren und bewertenISO/IEC 27001

    War: Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom (9.1 b–f).

  • 9.3ManagementbewertungISO/IEC 27001

    War: Sign-off is immutable and the required inputs are prompted. Two of the 9.3.2 inputs are not prompted for, and inputs are retyped rather than derived from records the product already holds.

  • 10.2Abweichung und KorrekturmaßnahmeISO/IEC 27001

    War: Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting ISMS change.

  • 4.1Die Organisation und ihr Umfeld verstehenISO/IEC 42001

    War: Issues are captured as text. 42001 also asks you to determine the organization's role for each AI system (provider, developer, deployer or user) and nothing here records that, so a system you deploy and a system you build carry the same context entry.

  • 4.2Wer ein Interesse hat und was er verlangtISO/IEC 42001

    War: One free-text field conflates needs with requirements, and there is no field for which requirements the management system will address. For AI this omission bites harder: the parties affected by an AI system are frequently not its customers, and nothing distinguishes the two.

  • 4.3Festlegen, was das KI-Managementsystem abdecktISO/IEC 42001

    War: The scope statement is an unversioned, unapproved column outside the document module, with no field for interfaces and dependencies. It also has no place to list the AI systems in scope, which is how a 42001 scope is normally read.

  • 5.2Eine KI-RichtlinieISO/IEC 42001

    War: Versioning and approval are strong. No flag identifies which document is the AI policy, and there is no record of it being communicated or made available. 42001 also expects the AI policy to be reconciled with other organizational policies, and nothing models that relationship.

  • 6.1.3Maßnahmen auswählen und angeben, welche geltenISO/IEC 42001

    War: The Statement of Applicability renders and hashes server-side, in this standard's own vocabulary. The seeded 42001 pack is a starting set rather than the full Annex A control list, so the check that no necessary control was omitted cannot yet be performed by the system.

  • 6.1.4Beurteilen, was ein KI-System den berührten Menschen antutISO/IEC 42001

    War: This has no counterpart in ISO 27001 and is the clause 42001 is really about. Impacts can be recorded as risks today, which is where an auditor will look, but there is no dedicated impact assessment holding the affected groups, the intended purpose and reasonably foreseeable misuse per AI system.

  • 6.2KI-Ziele und wie sie erreicht werdenISO/IEC 42001

    War: Objectives are captured and measured. Missing what will be done, what resources are needed, who is responsible, and how results will be evaluated.

  • 7.3Menschen bewusst machen, worum es gehtISO/IEC 42001

    War: Activity-level only. Audience is free text with no per-person link, so 'was this named employee made aware' cannot be answered.

  • 7.5Dokumentierte Information lenkenISO/IEC 42001

    War: Creation, versioning and approval are strong. Missing review cadence, classification, distribution record, retention and disposition, and any register of externally-originated documents.

  • 8.1Den Betrieb des Systems planen und steuernISO/IEC 42001

    War: Recurring obligations and machine-collected checks are real evidence of planned activity. Missing process criteria, control of externally provided processes, and review of unintended changes, the last of which matters more for AI, where a model can change behaviour without anyone changing the system.

  • 8.2KI-Risiko in geplanten Abständen und bei Änderungen beurteilenISO/IEC 42001

    War: Assessments are recorded as events with retained results, and the interval is planned rather than inferred. A change-triggered assessment is still one someone remembered to raise, and nothing in the product detects that a model, its data or its purpose changed.

  • 8.3Den Plan zur KI-Risikobehandlung umsetzenISO/IEC 42001

    War: Per-risk treatment plan and status. No record of the results of implementation, which this clause requires be retained.

  • 8.4Die Folgenabschätzung durchführen und das Ergebnis aufbewahrenISO/IEC 42001

    War: The operational counterpart of 6.1.4, and it inherits the same gap: the result is retained as a risk record rather than as an impact assessment in its own right, so an auditor asking for the assessment of one named AI system is handed a filtered risk list.

  • 9.1Überwachen, messen, analysieren und bewertenISO/IEC 42001

    War: Measurements are captured. Missing the methods that ensure valid results, who monitors, when results are analysed, and by whom.

  • 9.3ManagementbewertungISO/IEC 42001

    War: Sign-off is immutable and the required inputs are prompted. Inputs are retyped rather than derived from records the product already holds, and the prompts are the shared Harmonized Structure ones rather than 42001's own.

  • 10.2Abweichung und KorrekturmaßnahmeISO/IEC 42001

    War: Strong on correction, root cause and verification. Missing whether similar nonconformities exist elsewhere, a distinct effectiveness review, and a link to the resulting change to the management system.

1. August 2026

  • 4.4Das ISMS und die Prozesse, aus denen es bestehtISO/IEC 27001

    War: No process register and no record of how the processes interact.

  • 7.1Die Ressourcen, die das ISMS brauchtISO/IEC 27001

    War: Not modelled.

  • 7.4Über Sicherheit kommunizierenISO/IEC 27001

    War: No record of what is communicated, when, to whom, or how.

Nicht geschlossen, neu eingeordnet

2 Einträge haben sich geändert, weil wir entschieden haben, dass die Lücke eine Grenze jeder Software ist und kein Versäumnis von uns. Das als Lieferung zu zählen wäre dieselbe Übertreibung in die andere Richtung, deshalb steht es hier und nicht oben.

  • 5.1Eine Leitung, die das System wirklich trägt3. August 2026

    War: All eight demonstrations are answered from records held elsewhere in the ISMS, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.

  • 5.1Eine Leitung, die das System wirklich trägt3. August 2026

    War: The demonstrations are answered from records held elsewhere in the management system, so the evidence is assembled rather than asserted. But no software can show that top management personally did any of it. An auditor establishes that by interviewing them.

Warum auf dieser Seite sonst nichts steht

Ausgelieferte Funktionen sind leicht aufzulisten und beweisen wenig, denn das Änderungsprotokoll jedes Anbieters ist voll davon. Öffentlich eingestandene und dann geschlossene Lücken sind die einzigen Einträge, deren Veröffentlichung etwas kostet, denn sie verlangen, gesagt zu haben, dass etwas fehlte, während es fehlte. Das Register ist der Ort des aktuellen Stands, und es bleibt das Ehrliche, zuerst dort zu lesen.