'use client' import React, { useState, useEffect } from 'react' import { useRouter } from 'next/navigation' import { useSDK, Control as SDKControl, ControlType, ImplementationStatus } from '@/lib/sdk' import { StepHeader, STEP_EXPLANATIONS } from '@/components/sdk/StepHeader' // ============================================================================= // TYPES // ============================================================================= type DisplayControlType = 'preventive' | 'detective' | 'corrective' type DisplayCategory = 'technical' | 'organizational' | 'physical' type DisplayStatus = 'implemented' | 'partial' | 'planned' | 'not-implemented' interface DisplayControl { id: string name: string description: string type: ControlType category: string implementationStatus: ImplementationStatus evidence: string[] owner: string | null dueDate: Date | null code: string displayType: DisplayControlType displayCategory: DisplayCategory displayStatus: DisplayStatus effectivenessPercent: number linkedRequirements: string[] linkedEvidence: { id: string; title: string; status: string }[] lastReview: Date } // ============================================================================= // HELPER FUNCTIONS // ============================================================================= function mapControlTypeToDisplay(type: ControlType): DisplayCategory { switch (type) { case 'TECHNICAL': return 'technical' case 'ORGANIZATIONAL': return 'organizational' case 'PHYSICAL': return 'physical' default: return 'technical' } } function mapStatusToDisplay(status: ImplementationStatus): DisplayStatus { switch (status) { case 'IMPLEMENTED': return 'implemented' case 'PARTIAL': return 'partial' case 'NOT_IMPLEMENTED': return 'not-implemented' default: return 'not-implemented' } } // ============================================================================= // FALLBACK TEMPLATES // ============================================================================= interface ControlTemplate { id: string code: string name: string description: string type: ControlType displayType: DisplayControlType displayCategory: DisplayCategory category: string owner: string linkedRequirements: string[] } const controlTemplates: ControlTemplate[] = [ { id: 'ctrl-tom-001', code: 'TOM-001', name: 'Zugriffskontrolle', description: 'Rollenbasierte Zugriffskontrolle (RBAC) fuer alle Systeme', type: 'TECHNICAL', displayType: 'preventive', displayCategory: 'technical', category: 'Zutrittskontrolle', owner: 'IT Security', linkedRequirements: ['req-gdpr-32'], }, { id: 'ctrl-tom-002', code: 'TOM-002', name: 'Verschluesselung', description: 'Verschluesselung von Daten at rest und in transit', type: 'TECHNICAL', displayType: 'preventive', displayCategory: 'technical', category: 'Weitergabekontrolle', owner: 'IT Security', linkedRequirements: ['req-gdpr-32'], }, { id: 'ctrl-org-001', code: 'ORG-001', name: 'Datenschutzschulung', description: 'Jaehrliche Datenschutzschulung fuer alle Mitarbeiter', type: 'ORGANIZATIONAL', displayType: 'preventive', displayCategory: 'organizational', category: 'Schulung', owner: 'HR', linkedRequirements: ['req-gdpr-6', 'req-gdpr-32'], }, { id: 'ctrl-det-001', code: 'DET-001', name: 'Logging und Monitoring', description: 'Umfassendes Logging aller Datenzugriffe', type: 'TECHNICAL', displayType: 'detective', displayCategory: 'technical', category: 'Eingabekontrolle', owner: 'IT Operations', linkedRequirements: ['req-gdpr-32', 'req-nis2-21'], }, { id: 'ctrl-cor-001', code: 'COR-001', name: 'Incident Response', description: 'Prozess zur Behandlung von Datenschutzvorfaellen', type: 'ORGANIZATIONAL', displayType: 'corrective', displayCategory: 'organizational', category: 'Incident Management', owner: 'CISO', linkedRequirements: ['req-gdpr-32', 'req-nis2-21'], }, { id: 'ctrl-ai-001', code: 'AI-001', name: 'KI-Risikomonitoring', description: 'Kontinuierliche Ueberwachung von KI-Systemrisiken', type: 'TECHNICAL', displayType: 'detective', displayCategory: 'technical', category: 'KI-Governance', owner: 'AI Team', linkedRequirements: ['req-ai-act-9', 'req-ai-act-13'], }, ] // ============================================================================= // COMPONENTS // ============================================================================= function ControlCard({ control, onStatusChange, onEffectivenessChange, onLinkEvidence, }: { control: DisplayControl onStatusChange: (status: ImplementationStatus) => void onEffectivenessChange: (effectivenessPercent: number) => void onLinkEvidence: () => void }) { const [showEffectivenessSlider, setShowEffectivenessSlider] = useState(false) const typeColors = { preventive: 'bg-blue-100 text-blue-700', detective: 'bg-purple-100 text-purple-700', corrective: 'bg-orange-100 text-orange-700', } const categoryColors = { technical: 'bg-green-100 text-green-700', organizational: 'bg-yellow-100 text-yellow-700', physical: 'bg-gray-100 text-gray-700', } const statusColors = { implemented: 'border-green-200 bg-green-50', partial: 'border-yellow-200 bg-yellow-50', planned: 'border-blue-200 bg-blue-50', 'not-implemented': 'border-red-200 bg-red-50', } const statusLabels = { implemented: 'Implementiert', partial: 'Teilweise', planned: 'Geplant', 'not-implemented': 'Nicht implementiert', } return (
{control.code} {control.displayType === 'preventive' ? 'Praeventiv' : control.displayType === 'detective' ? 'Detektiv' : 'Korrektiv'} {control.displayCategory === 'technical' ? 'Technisch' : control.displayCategory === 'organizational' ? 'Organisatorisch' : 'Physisch'}

{control.name}

{control.description}

setShowEffectivenessSlider(!showEffectivenessSlider)} > Wirksamkeit {control.effectivenessPercent}%
= 80 ? 'bg-green-500' : control.effectivenessPercent >= 50 ? 'bg-yellow-500' : 'bg-red-500' }`} style={{ width: `${control.effectivenessPercent}%` }} />
{showEffectivenessSlider && (
onEffectivenessChange(Number(e.target.value))} className="w-full" />
)}
Verantwortlich: {control.owner || 'Nicht zugewiesen'}
Letzte Pruefung: {control.lastReview.toLocaleDateString('de-DE')}
{control.linkedRequirements.slice(0, 3).map(req => ( {req} ))} {control.linkedRequirements.length > 3 && ( +{control.linkedRequirements.length - 3} )}
{statusLabels[control.displayStatus]}
{/* Linked Evidence */} {control.linkedEvidence.length > 0 && (
Nachweise:
{control.linkedEvidence.map(ev => ( {ev.title} ))}
)}
) } function AddControlForm({ onSubmit, onCancel, }: { onSubmit: (data: { name: string; description: string; type: ControlType; category: string; owner: string }) => void onCancel: () => void }) { const [formData, setFormData] = useState({ name: '', description: '', type: 'TECHNICAL' as ControlType, category: '', owner: '', }) return (

Neue Kontrolle

setFormData({ ...formData, name: e.target.value })} placeholder="z.B. Zugriffskontrolle" className="w-full px-4 py-2 border border-gray-300 rounded-lg focus:ring-2 focus:ring-purple-500 focus:border-transparent" />