TISAX
Who it's for
Suppliers and service providers in the automotive industry.
Problems we solve
Being repeatedly asked for security assessments by different automakers, and unfamiliarity with VDA ISA requirements.
Benefits
Pass the TISAX assessment and share results on the platform, avoiding duplicate audits and meeting automaker requirements.
TISAX overview
Many automotive suppliers and service providers handle highly sensitive customer information, so customers often require proof of information-security compliance — for example, assessment against the German Association of the Automotive Industry (VDA) Information Security Assessment (ISA). Because manufacturers previously assessed suppliers independently and many suppliers underwent repeated identical assessments, in early 2017 the VDA established a new mechanism: TISAX (Trusted Information Security Assessment Exchange). Through the TISAX platform, companies share their security-assessment results across the industry; results are valid for three years.
Assessment scope
The scope describes the boundary of the assessment: any part of the company that handles partners' confidential information falls within scope. A precise scope is essential both to satisfy partner requirements and to allow the assessment provider to calculate costs reasonably. Assessment objectives and levels define the requirements the security-management system must meet.
Implementation in practice
- Gap analysis: through interviews, questionnaires, training and document review, understand the gap between current practice and the assessment catalogue, secure management support and set a customized project timeline.
- Risk assessment: based on scope and gap analysis, perform asset inventory and risk analysis, and build a risk-treatment plan; address personal-data protection to meet legal requirements.
- Documentation: based on the risk analysis, define controls and documents following the PDCA model, building policy, procedure, standard and form levels, with training for relevant personnel.
- Execution records: implement controls, monitor and measure against objectives, and rehearse business-continuity and incident-handling plans.
- Self-assessment: tune the system to the target maturity level and perform a self-assessment per the ISA standard (VDA ISA) before the formal TISAX assessment.
Interested in adoption and consulting? Contact us and a specialist will assist you.
IngSafe