{"id":1955,"date":"2025-12-17T16:21:12","date_gmt":"2025-12-17T16:21:12","guid":{"rendered":"https:\/\/icompliance.eu\/?p=1955"},"modified":"2025-12-17T20:44:50","modified_gmt":"2025-12-17T20:44:50","slug":"implementing-tisax-in-your-organisation-a-practical-guide-for-automotive-suppliers","status":"publish","type":"post","link":"https:\/\/icompliance.eu\/en\/implementing-tisax-in-your-organisation-a-practical-guide-for-automotive-suppliers\/","title":{"rendered":"Implementing TISAX in Your Organisation: A practical guide for automotive suppliers"},"content":{"rendered":"<h1 data-start=\"0\" data-end=\"175\">Implementing TISAX in your organisation: a practical guide for automotive suppliers<\/h1>\n<p data-start=\"177\" data-end=\"433\">Pressure from car manufacturers and major integrators to strengthen information security has led TISAX (Trusted Information Security Assessment Exchange) to become practically a &#8220;ticket of entry&#8221; into the European automotive supply chain.<\/p>\n<p data-start=\"435\" data-end=\"606\">For many Portuguese companies, the question is no longer <strong data-start=\"489\" data-end=\"497\">&#8220;if&#8221;<\/strong> they will have to implement TISAX, but <strong data-start=\"532\" data-end=\"553\">&#8220;when&#8221; and &#8220;how&#8221;<\/strong> to do so efficiently and in line with their business.<\/p>\n<p data-start=\"608\" data-end=\"794\">In this article, I explain in practical terms what TISAX is, how it relates to ISO 27001, and what steps are essential to prepare your organisation for a successful assessment.<\/p>\n<h2 data-start=\"801\" data-end=\"821\">1. What is TISAX?<\/h2>\n<p data-start=\"823\" data-end=\"1131\">TISAX is a mechanism for <strong data-start=\"847\" data-end=\"912\">assessing and sharing information security results<\/strong>, developed specifically for the automotive sector. It is managed by the <strong data-start=\"981\" data-end=\"1000\">ENX Association<\/strong> on behalf of the German automotive industry association (VDA \u2013 Verband der Automobilindustrie). <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/learn.microsoft.com\/pt-pt\/azure\/compliance\/offerings\/offering-tisax\" target=\"_blank\" rel=\"noopener\">Microsoft Learn+1<\/a> <\/p>\n<p data-start=\"1133\" data-end=\"1248\">Instead of each manufacturer requiring its own audits of each supplier, TISAX creates a central platform where:<\/p>\n<ul data-start=\"1250\" data-end=\"1518\">\n<li data-start=\"1250\" data-end=\"1305\">\n<p data-start=\"1252\" data-end=\"1305\">companies are assessed by recognised auditors,<\/p>\n<\/li>\n<li data-start=\"1306\" data-end=\"1382\">\n<p data-start=\"1308\" data-end=\"1382\">obtain a <strong data-start=\"1317\" data-end=\"1334\">&#8220;TISAX label&#8221;<\/strong> with a specific assessment level\/objective,<\/p>\n<\/li>\n<li data-start=\"1383\" data-end=\"1518\">\n<p data-start=\"1385\" data-end=\"1518\">and <strong data-start=\"1387\" data-end=\"1415\">share this result<\/strong> with various business partners, avoiding duplicate audits. <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/portal.enx.com\/handbook\/tisax-participant-handbook.html\" target=\"_blank\" rel=\"noopener\">portal.enx.com+1<\/a><\/p>\n<\/li>\n<\/ul>\n<p data-start=\"1520\" data-end=\"1867\">It is important to note that we are talking about a <strong data-start=\"1556\" data-end=\"1573\">&#8220;TISAX label&#8221;<\/strong>, not a traditional ISO certification. The standard is based on <strong data-start=\"1638\" data-end=\"1692\">the VDA ISA (Information Security Assessment) catalogue<\/strong>, which is built on <strong data-start=\"1717\" data-end=\"1742\">ISO\/IEC 27001 and 27002<\/strong> but adapted to the automotive context (protection of prototypes, tests, events, etc.). <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/learn.microsoft.com\/pt-pt\/azure\/compliance\/offerings\/offering-tisax\" target=\"_blank\" rel=\"noopener\">Microsoft Learn+2<\/a> <\/p>\n<h2 data-start=\"1874\" data-end=\"1932\">2. TISAX vs. ISO 27001: competitors or complementary?<\/h2>\n<p data-start=\"1934\" data-end=\"2016\">For many organisations, the question is: <em data-start=\"1972\" data-end=\"2016\">&#8220;If I already have ISO 27001, do I need TISAX?&#8221;<\/em><\/p>\n<p data-start=\"2018\" data-end=\"2164\">The short answer is: <strong data-start=\"2038\" data-end=\"2060\">probably yes<\/strong>, if you want to work or continue working with certain OEMs or major automotive suppliers.<\/p>\n<ul data-start=\"2166\" data-end=\"2628\">\n<li data-start=\"2166\" data-end=\"2274\">\n<p data-start=\"2168\" data-end=\"2274\"><strong data-start=\"2170\" data-end=\"2183\">ISO 27001<\/strong> defines the requirements for an <strong data-start=\"2213\" data-end=\"2273\">Information Security Management System (ISMS)<\/strong>.<\/p>\n<\/li>\n<li data-start=\"2275\" data-end=\"2628\">\n<p data-start=\"2277\" data-end=\"2390\">TISAX <strong data-start=\"2283\" data-end=\"2300\">uses this foundation<\/strong> but translates it into sector-specific requirements and assessment objectives, including:<\/p>\n<ul data-start=\"2393\" data-end=\"2628\">\n<li data-start=\"2393\" data-end=\"2438\">\n<p data-start=\"2395\" data-end=\"2438\">protection of prototypes and test vehicles;<\/p>\n<\/li>\n<li data-start=\"2441\" data-end=\"2486\">\n<p data-start=\"2443\" data-end=\"2486\">safety of facilities and test tracks;<\/p>\n<\/li>\n<li data-start=\"2489\" data-end=\"2547\">\n<p data-start=\"2491\" data-end=\"2547\">secure management of development and production data;<\/p>\n<\/li>\n<li data-start=\"2550\" data-end=\"2628\">\n<p data-start=\"2552\" data-end=\"2628\">additional requirements associated with &#8220;high&#8221; and &#8220;very high&#8221; protection levels.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p data-start=\"2630\" data-end=\"2641\">In practice:<\/p>\n<ul data-start=\"2643\" data-end=\"2902\">\n<li data-start=\"2643\" data-end=\"2743\">\n<p data-start=\"2645\" data-end=\"2743\">if <strong data-start=\"2648\" data-end=\"2668\">you already have ISO 27001<\/strong>, you have an excellent foundation and the TISAX project will be an <strong data-start=\"2719\" data-end=\"2742\">&#8220;adjustment and extension&#8221;<\/strong>;<\/p>\n<\/li>\n<li data-start=\"2744\" data-end=\"2902\">\n<p data-start=\"2746\" data-end=\"2902\">If <strong data-start=\"2749\" data-end=\"2766\">you do not already have one<\/strong>, the implementation of TISAX can (and should) be considered as an <strong data-start=\"2832\" data-end=\"2863\">ISMS aligned with ISO 27001<\/strong>, so as not to &#8220;build everything twice&#8221;.<\/p>\n<\/li>\n<\/ul>\n<h2 data-start=\"2909\" data-end=\"2967\">3. Starting point: clarifying requirements and maturity<\/h2>\n<p data-start=\"2969\" data-end=\"3049\">Before launching a &#8220;mega-project,&#8221; it is crucial to answer three simple questions:<\/p>\n<ol data-start=\"3051\" data-end=\"3857\">\n<li data-start=\"3051\" data-end=\"3413\">\n<p data-start=\"3054\" data-end=\"3148\"><strong data-start=\"3054\" data-end=\"3105\">Which customers request TISAX \u2013 and with what requirements?<\/strong><br data-start=\"3105\" data-end=\"3108\">Normally, the OEM or customer specifies:<\/p>\n<ul data-start=\"3152\" data-end=\"3413\">\n<li data-start=\"3152\" data-end=\"3269\">\n<p data-start=\"3154\" data-end=\"3269\"><strong data-start=\"3157\" data-end=\"3189\">TISAX assessment objectives<\/strong> (TISAX Assessment Objectives \/ Labels); <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/vda-isa-berater.com\/en\/tisax-the-different-assessment-levels-and-assessment-objectives\/\" target=\"_blank\" rel=\"noopener\">VDA ISA Consultant+1<\/a><\/p>\n<\/li>\n<li data-start=\"3273\" data-end=\"3413\">\n<p data-start=\"3275\" data-end=\"3413\">the <strong data-start=\"3277\" data-end=\"3299\">assessment level<\/strong> (AL2 \u2013 remote document assessment; AL3 \u2013 assessment with on-site visits). <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/www.dataguard.com\/blog\/levels-in-the-assessment-on-tisax\" target=\"_blank\" rel=\"noopener\">dataguard.com+1<\/a><\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li data-start=\"3415\" data-end=\"3659\">\n<p data-start=\"3418\" data-end=\"3448\"><strong data-start=\"3418\" data-end=\"3446\">What is the relevant scope?<\/strong><\/p>\n<ul data-start=\"3452\" data-end=\"3659\">\n<li data-start=\"3452\" data-end=\"3520\">\n<p data-start=\"3454\" data-end=\"3520\">country(ies), locations, engineering centres, critical partners;<\/p>\n<\/li>\n<li data-start=\"3524\" data-end=\"3608\">\n<p data-start=\"3526\" data-end=\"3608\">processes (development, prototyping, testing, production, shared services);<\/p>\n<\/li>\n<li data-start=\"3612\" data-end=\"3659\">\n<p data-start=\"3614\" data-end=\"3659\">critical information systems and applications.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li data-start=\"3661\" data-end=\"3857\">\n<p data-start=\"3664\" data-end=\"3721\"><strong data-start=\"3664\" data-end=\"3719\">What is the current maturity of information security?<\/strong><\/p>\n<ul data-start=\"3725\" data-end=\"3857\">\n<li data-start=\"3725\" data-end=\"3800\">\n<p data-start=\"3727\" data-end=\"3800\">Are there already security policies, access management and incident management in place?<\/p>\n<\/li>\n<li data-start=\"3804\" data-end=\"3857\">\n<p data-start=\"3806\" data-end=\"3857\">Are there records and evidence, or is everything &#8216;informal&#8217;?<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<p data-start=\"3859\" data-end=\"4006\">An initial <strong data-start=\"3863\" data-end=\"3881\">gap analysis<\/strong> against the VDA ISA (or against your current ISO 27001) is the logical starting point. <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/www.dataguard.com\/downloads\/roadmap-for-the-assessment-on-tisax\/\" target=\"_blank\" rel=\"noopener\">dataguard.com+1<\/a><\/p>\n<h2 data-start=\"4013\" data-end=\"4061\">4. Seven steps to implement TISAX in practice<\/h2>\n<h3 data-start=\"4063\" data-end=\"4099\">Step 1 \u2013 Define the TISAX scope<\/h3>\n<p data-start=\"4101\" data-end=\"4181\">The scope is the &#8216;boundary&#8217; of the assessment. It must be very well thought out, because it affects: <\/p>\n<ul data-start=\"4183\" data-end=\"4271\">\n<li data-start=\"4183\" data-end=\"4212\">\n<p data-start=\"4185\" data-end=\"4212\">the implementation effort,<\/p>\n<\/li>\n<li data-start=\"4213\" data-end=\"4236\">\n<p data-start=\"4215\" data-end=\"4236\">the cost of the assessment,<\/p>\n<\/li>\n<li data-start=\"4237\" data-end=\"4271\">\n<p data-start=\"4239\" data-end=\"4271\">and the value for its customers.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"4273\" data-end=\"4292\">It usually includes:<\/p>\n<ul data-start=\"4294\" data-end=\"4539\">\n<li data-start=\"4294\" data-end=\"4351\">\n<p data-start=\"4296\" data-end=\"4351\">Legal entities involved (company A, subsidiary B, etc.)<\/p>\n<\/li>\n<li data-start=\"4352\" data-end=\"4428\">\n<p data-start=\"4354\" data-end=\"4428\">Physical locations (headquarters, R&amp;D centre, factory, testing laboratory)<\/p>\n<\/li>\n<li data-start=\"4429\" data-end=\"4502\">\n<p data-start=\"4431\" data-end=\"4502\">Processes and services (development, prototyping, IT services, etc.)<\/p>\n<\/li>\n<li data-start=\"4503\" data-end=\"4539\">\n<p data-start=\"4505\" data-end=\"4539\">Relevant information systems.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"4541\" data-end=\"4668\">This definition is subsequently recorded on the <strong data-start=\"4586\" data-end=\"4600\">ENX portal<\/strong> as the scope of the assessment. <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/portal.enx.com\/handbook\/tisax-participant-handbook.html\" target=\"_blank\" rel=\"noopener\">portal.enx.com+1<\/a><\/p>\n<h3 data-start=\"4675\" data-end=\"4727\">Step 2 \u2013 Establish the project and governance team<\/h3>\n<p data-start=\"4729\" data-end=\"4808\">TISAX is not an &#8220;IT-only&#8221; project. It involves people, processes and technology. <\/p>\n<p data-start=\"4810\" data-end=\"4835\">Typically, there should be:<\/p>\n<ul data-start=\"4837\" data-end=\"5219\">\n<li data-start=\"4837\" data-end=\"4891\">\n<p data-start=\"4839\" data-end=\"4891\"><strong data-start=\"4839\" data-end=\"4858\">Top sponsor<\/strong> (General Management\/Administration);<\/p>\n<\/li>\n<li data-start=\"4892\" data-end=\"4977\">\n<p data-start=\"4894\" data-end=\"4977\">an <strong data-start=\"4897\" data-end=\"4941\">information security officer<\/strong> (CISO, IT Manager, or equivalent);<\/p>\n<\/li>\n<li data-start=\"4978\" data-end=\"5219\">\n<p data-start=\"4980\" data-end=\"4998\">representatives of:<\/p>\n<ul data-start=\"5001\" data-end=\"5219\">\n<li data-start=\"5001\" data-end=\"5022\">\n<p data-start=\"5003\" data-end=\"5022\">IT\/Infrastructure;<\/p>\n<\/li>\n<li data-start=\"5025\" data-end=\"5048\">\n<p data-start=\"5027\" data-end=\"5048\">Engineering\/Operations;<\/p>\n<\/li>\n<li data-start=\"5051\" data-end=\"5070\">\n<p data-start=\"5053\" data-end=\"5070\">Human Resources;<\/p>\n<\/li>\n<li data-start=\"5073\" data-end=\"5094\">\n<p data-start=\"5075\" data-end=\"5094\">Legal\/Contracts;<\/p>\n<\/li>\n<li data-start=\"5097\" data-end=\"5147\">\n<p data-start=\"5099\" data-end=\"5147\">Data Protection (DPO) \u2013 to align with GDPR;<\/p>\n<\/li>\n<li data-start=\"5150\" data-end=\"5219\">\n<p data-start=\"5152\" data-end=\"5219\">Suppliers\/Purchasing (when critical services are outsourced).<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p data-start=\"5221\" data-end=\"5233\">Define it right away:<\/p>\n<ul data-start=\"5235\" data-end=\"5329\">\n<li data-start=\"5235\" data-end=\"5261\">\n<p data-start=\"5237\" data-end=\"5261\"><strong data-start=\"5237\" data-end=\"5260\">security committee;<\/strong><\/p>\n<\/li>\n<li data-start=\"5262\" data-end=\"5291\">\n<p data-start=\"5264\" data-end=\"5291\">roles and responsibilities;<\/p>\n<\/li>\n<li data-start=\"5292\" data-end=\"5329\">\n<p data-start=\"5294\" data-end=\"5329\">meeting schedule and reporting.<\/p>\n<\/li>\n<\/ul>\n<h3 data-start=\"5336\" data-end=\"5398\">Step 3 \u2013 Map controls based on VDA ISA \/ ISO 27001<\/h3>\n<p data-start=\"5400\" data-end=\"5492\">The next step is to &#8216;translate&#8217; the VDA ISA into the reality of your company. In practical terms: <\/p>\n<ol data-start=\"5494\" data-end=\"6127\">\n<li data-start=\"5494\" data-end=\"5661\">\n<p data-start=\"5497\" data-end=\"5535\">Create a <strong data-start=\"5507\" data-end=\"5530\">control matrix<\/strong> with:<\/p>\n<ul data-start=\"5539\" data-end=\"5661\">\n<li data-start=\"5539\" data-end=\"5592\">\n<p data-start=\"5541\" data-end=\"5592\">relevant VDA ISA clauses \/ ISO 27001 controls;<\/p>\n<\/li>\n<li data-start=\"5596\" data-end=\"5626\">\n<p data-start=\"5598\" data-end=\"5626\">internal processes affected;<\/p>\n<\/li>\n<li data-start=\"5630\" data-end=\"5661\">\n<p data-start=\"5632\" data-end=\"5661\">responsible for each measure.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li data-start=\"5663\" data-end=\"6127\">\n<p data-start=\"5666\" data-end=\"5708\">Prioritise controls in typical areas such as:<\/p>\n<ul data-start=\"5712\" data-end=\"6127\">\n<li data-start=\"5712\" data-end=\"5794\">\n<p data-start=\"5714\" data-end=\"5794\"><strong data-start=\"5714\" data-end=\"5740\">Governance and policies<\/strong> (security policy, information classification);<\/p>\n<\/li>\n<li data-start=\"5798\" data-end=\"5831\">\n<p data-start=\"5800\" data-end=\"5831\"><strong data-start=\"5800\" data-end=\"5830\">Asset and access management;<\/strong><\/p>\n<\/li>\n<li data-start=\"5835\" data-end=\"5870\">\n<p data-start=\"5837\" data-end=\"5870\"><strong data-start=\"5837\" data-end=\"5869\">Physical and environmental safety;<\/strong><\/p>\n<\/li>\n<li data-start=\"5874\" data-end=\"5917\">\n<p data-start=\"5876\" data-end=\"5917\"><strong data-start=\"5876\" data-end=\"5916\">Security in development and testing;<\/strong><\/p>\n<\/li>\n<li data-start=\"5921\" data-end=\"5962\">\n<p data-start=\"5923\" data-end=\"5962\"><strong data-start=\"5923\" data-end=\"5961\">Backup, continuity, and recovery;<\/strong><\/p>\n<\/li>\n<li data-start=\"5966\" data-end=\"6006\">\n<p data-start=\"5968\" data-end=\"6006\"><strong data-start=\"5968\" data-end=\"6005\">Security incident management;<\/strong><\/p>\n<\/li>\n<li data-start=\"6010\" data-end=\"6054\">\n<p data-start=\"6012\" data-end=\"6054\"><strong data-start=\"6012\" data-end=\"6053\">Supplier and contract security;<\/strong><\/p>\n<\/li>\n<li data-start=\"6058\" data-end=\"6127\">\n<p data-start=\"6060\" data-end=\"6127\"><strong data-start=\"6060\" data-end=\"6108\">Specific prototype and testing requirements<\/strong> (where applicable).<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h3 data-start=\"6134\" data-end=\"6205\">Step 4 \u2013 Implement priority technical and organisational measures<\/h3>\n<p data-start=\"6207\" data-end=\"6258\">With the gap matrix defined, it is time to execute.<\/p>\n<p data-start=\"6260\" data-end=\"6332\">Some examples of measures that recur frequently in TISAX projects:<\/p>\n<ul data-start=\"6334\" data-end=\"6921\">\n<li data-start=\"6334\" data-end=\"6433\">\n<p data-start=\"6336\" data-end=\"6433\">reinforcement of <strong data-start=\"6347\" data-end=\"6377\">physical access controls<\/strong> (turnstiles, visitor registration, segregated areas);<\/p>\n<\/li>\n<li data-start=\"6434\" data-end=\"6538\">\n<p data-start=\"6436\" data-end=\"6538\">improvement of <strong data-start=\"6448\" data-end=\"6478\">logical access controls<\/strong> (MFA, privilege management, periodic access review);<\/p>\n<\/li>\n<li data-start=\"6539\" data-end=\"6587\">\n<p data-start=\"6541\" data-end=\"6587\">encryption of data at rest and in transit;<\/p>\n<\/li>\n<li data-start=\"6588\" data-end=\"6657\">\n<p data-start=\"6590\" data-end=\"6657\">formal <strong data-start=\"6615\" data-end=\"6645\">vulnerability management<\/strong> and patching procedures;<\/p>\n<\/li>\n<li data-start=\"6658\" data-end=\"6848\">\n<p data-start=\"6660\" data-end=\"6698\">clear policies and procedures for:<\/p>\n<ul data-start=\"6701\" data-end=\"6848\">\n<li data-start=\"6701\" data-end=\"6731\">\n<p data-start=\"6703\" data-end=\"6731\">information classification;<\/p>\n<\/li>\n<li data-start=\"6734\" data-end=\"6781\">\n<p data-start=\"6736\" data-end=\"6781\">trabalho remoto e uso de dispositivos m\u00f3veis;<\/p>\n<\/li>\n<li data-start=\"6784\" data-end=\"6848\">\n<p data-start=\"6786\" data-end=\"6848\">management of information media (USB, external drives, etc.);<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li data-start=\"6849\" data-end=\"6921\">\n<p data-start=\"6851\" data-end=\"6921\">contracts and <strong data-start=\"6863\" data-end=\"6920\">NDAs tailored to prototypes and confidential information<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"6923\" data-end=\"7056\">The goal is not to achieve &#8220;perfection,&#8221; but rather <strong data-start=\"6973\" data-end=\"7014\">consistent and demonstrable maturity<\/strong> (with evidence) in the relevant domains.<\/p>\n<h3 data-start=\"7063\" data-end=\"7110\">Step 5 \u2013 Document processes and evidence<\/h3>\n<p data-start=\"7112\" data-end=\"7197\">In a TISAX project, <strong data-start=\"7131\" data-end=\"7196\">anything that is not documented &#8220;does not exist&#8221; in the eyes of the auditor<\/strong>.<\/p>\n<p data-start=\"7199\" data-end=\"7229\">It is essential to produce and maintain:<\/p>\n<ul data-start=\"7231\" data-end=\"7532\">\n<li data-start=\"7231\" data-end=\"7265\">\n<p data-start=\"7233\" data-end=\"7265\">policies approved by management;<\/p>\n<\/li>\n<li data-start=\"7266\" data-end=\"7366\">\n<p data-start=\"7268\" data-end=\"7366\">operational procedures (e.g., incident management, access management, onboarding\/offboarding);<\/p>\n<\/li>\n<li data-start=\"7367\" data-end=\"7532\">\n<p data-start=\"7369\" data-end=\"7378\">records:<\/p>\n<ul data-start=\"7381\" data-end=\"7532\">\n<li data-start=\"7381\" data-end=\"7399\">\n<p data-start=\"7383\" data-end=\"7399\">access logs;<\/p>\n<\/li>\n<li data-start=\"7402\" data-end=\"7432\">\n<p data-start=\"7404\" data-end=\"7432\">vulnerability reports;<\/p>\n<\/li>\n<li data-start=\"7435\" data-end=\"7458\">\n<p data-start=\"7437\" data-end=\"7458\">training records;<\/p>\n<\/li>\n<li data-start=\"7461\" data-end=\"7492\">\n<p data-start=\"7463\" data-end=\"7492\">atas de comit\u00e9s de seguran\u00e7a;<\/p>\n<\/li>\n<li data-start=\"7495\" data-end=\"7532\">\n<p data-start=\"7497\" data-end=\"7532\">continuity test records.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p data-start=\"7534\" data-end=\"7731\">The TISAX handbook itself emphasises the need for <strong data-start=\"7585\" data-end=\"7644\">process documentation and evidence of implementation<\/strong> to demonstrate the maturity level of the ISMS. <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/enx.com\/handbook\/TISAX%20Participant%20Handbook.pdf\" target=\"_blank\" rel=\"noopener\">enx.com<\/a><\/p>\n<h3 data-start=\"7738\" data-end=\"7794\">Step 6 \u2013 Registration on the ENX portal and selection of the auditor<\/h3>\n<p data-start=\"7796\" data-end=\"7846\">With the ISMS reasonably structured, it is time to:<\/p>\n<ol data-start=\"7848\" data-end=\"8383\">\n<li data-start=\"7848\" data-end=\"8000\">\n<p data-start=\"7851\" data-end=\"7902\"><strong data-start=\"7851\" data-end=\"7891\">Register the organisation on the ENX portal<\/strong> and define:<\/p>\n<ul data-start=\"7906\" data-end=\"8000\">\n<li data-start=\"7906\" data-end=\"7925\">\n<p data-start=\"7908\" data-end=\"7925\">company data;<\/p>\n<\/li>\n<li data-start=\"7929\" data-end=\"7959\">\n<p data-start=\"7931\" data-end=\"7959\">scope of the assessment;<\/p>\n<\/li>\n<li data-start=\"7963\" data-end=\"8000\">\n<p data-start=\"7965\" data-end=\"8000\">TISAX objectives and desired level.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<li data-start=\"8002\" data-end=\"8220\">\n<p data-start=\"8005\" data-end=\"8220\"><strong data-start=\"8005\" data-end=\"8064\">Select an ENX-approved audit provider<\/strong><br data-start=\"8064\" data-end=\"8067\">There are several bodies (T\u00dcV, SGS, etc.) authorised to conduct TISAX assessments and issue the respective label. <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/www.sgs.com\/en-pt\/services\/trusted-information-security-assessment-exchange-tisax\" target=\"_blank\" rel=\"noopener\">SGSCorp+2T\u00dcV S\u00dcD+2<\/a><\/p>\n<\/li>\n<li data-start=\"8222\" data-end=\"8383\">\n<p data-start=\"8225\" data-end=\"8247\">Agree with the auditor:<\/p>\n<ul data-start=\"8251\" data-end=\"8383\">\n<li data-start=\"8251\" data-end=\"8268\">\n<p data-start=\"8253\" data-end=\"8268\">scheduling;<\/p>\n<\/li>\n<li data-start=\"8272\" data-end=\"8334\">\n<p data-start=\"8274\" data-end=\"8334\">type of assessment (AL2 \u2013 remote; AL3 \u2013 with on-site visits);<\/p>\n<\/li>\n<li data-start=\"8338\" data-end=\"8360\">\n<p data-start=\"8340\" data-end=\"8360\">working languages;<\/p>\n<\/li>\n<li data-start=\"8364\" data-end=\"8383\">\n<p data-start=\"8366\" data-end=\"8383\">locations included.<\/p>\n<\/li>\n<\/ul>\n<\/li>\n<\/ol>\n<h3 data-start=\"8390\" data-end=\"8441\">Step 7 \u2013 Prepare and conduct the TISAX assessment<\/h3>\n<p data-start=\"8443\" data-end=\"8579\">In terms of auditing, the TISAX process has two main phases: <strong data-start=\"8508\" data-end=\"8522\">preparation<\/strong> and <strong data-start=\"8525\" data-end=\"8538\">assessment<\/strong>. <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/www.tuvsud.com\/en\/services\/management-system-certification\/tisax\" target=\"_blank\" rel=\"noopener\">T\u00dcV S\u00dcD+1<\/a><\/p>\n<p data-start=\"8581\" data-end=\"8596\"><strong data-start=\"8581\" data-end=\"8596\">Preparation:<\/strong><\/p>\n<ul data-start=\"8598\" data-end=\"8898\">\n<li data-start=\"8598\" data-end=\"8666\">\n<p data-start=\"8600\" data-end=\"8666\">conduct a detailed <strong data-start=\"8612\" data-end=\"8631\">self-assessment<\/strong> using the VDA ISA questionnaire;<\/p>\n<\/li>\n<li data-start=\"8667\" data-end=\"8727\">\n<p data-start=\"8669\" data-end=\"8727\">validate responses and associated evidence internally;<\/p>\n<\/li>\n<li data-start=\"8728\" data-end=\"8804\">\n<p data-start=\"8730\" data-end=\"8804\">ensure that all documentation is consolidated and easily accessible;<\/p>\n<\/li>\n<li data-start=\"8805\" data-end=\"8898\">\n<p data-start=\"8807\" data-end=\"8898\">prepare the teams that will interact with the auditor (briefings, mock interviews).<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"8900\" data-end=\"8914\"><strong data-start=\"8900\" data-end=\"8914\">Assessment:<\/strong><\/p>\n<ul data-start=\"8916\" data-end=\"9144\">\n<li data-start=\"8916\" data-end=\"8970\">\n<p data-start=\"8918\" data-end=\"8970\">interviews with managers and operational teams;<\/p>\n<\/li>\n<li data-start=\"8971\" data-end=\"9002\">\n<p data-start=\"8973\" data-end=\"9002\">detailed document analysis;<\/p>\n<\/li>\n<li data-start=\"9003\" data-end=\"9090\">\n<p data-start=\"9005\" data-end=\"9090\">on-site verification (AL3): facilities, physical controls, procedures in place;<\/p>\n<\/li>\n<li data-start=\"9091\" data-end=\"9144\">\n<p data-start=\"9093\" data-end=\"9144\">identification of non-conformities and recommendations.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"9146\" data-end=\"9362\">After the assessment is completed, the <strong data-start=\"9185\" data-end=\"9204\">TISAX report<\/strong> is issued, and \u2013 if the result is positive \u2013 the <strong data-start=\"9242\" data-end=\"9257\">TISAX label <\/strong>is registered on the ENX portal to be shared with your partners. <a class=\"flex h-4.5 overflow-hidden rounded-xl px-2 text-[9px] font-medium transition-colors duration-150 ease-in-out text-token-text-secondary! bg-[#F4F4F4]! dark:bg-[#303030]!\" href=\"https:\/\/portal.enx.com\/handbook\/tisax-participant-handbook.html\" target=\"_blank\" rel=\"noopener\">portal.enx.com+2<\/a><\/p>\n<h2 data-start=\"9369\" data-end=\"9405\">5. Best practices and mistakes to avoid<\/h2>\n<p data-start=\"9407\" data-end=\"9425\"><strong data-start=\"9407\" data-end=\"9425\">Best practices:<\/strong><\/p>\n<ul data-start=\"9427\" data-end=\"9761\">\n<li data-start=\"9427\" data-end=\"9491\">\n<p data-start=\"9429\" data-end=\"9491\">Treat TISAX as a <strong data-start=\"9450\" data-end=\"9472\">business project<\/strong>, not just an IT project.<\/p>\n<\/li>\n<li data-start=\"9492\" data-end=\"9573\">\n<p data-start=\"9494\" data-end=\"9573\">Leverage synergies with <strong data-start=\"9519\" data-end=\"9572\">ISO 27001, GDPR, and other compliance requirements<\/strong>.<\/p>\n<\/li>\n<li data-start=\"9574\" data-end=\"9676\">\n<p data-start=\"9576\" data-end=\"9676\">Maintain an <strong data-start=\"9586\" data-end=\"9618\">internal communication plan<\/strong> so that employees understand the &#8220;why&#8221; behind the changes.<\/p>\n<\/li>\n<li data-start=\"9677\" data-end=\"9761\">\n<p data-start=\"9679\" data-end=\"9761\">Invest in <strong data-start=\"9691\" data-end=\"9712\">ongoing training<\/strong> in information security and awareness.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"9763\" data-end=\"9784\"><strong data-start=\"9763\" data-end=\"9784\">Common mistakes:<\/strong><\/p>\n<ul data-start=\"9786\" data-end=\"10107\">\n<li data-start=\"9786\" data-end=\"9858\">\n<p data-start=\"9788\" data-end=\"9858\">Starting with the checklist without an overall view of risks and priorities.<\/p>\n<\/li>\n<li data-start=\"9859\" data-end=\"9959\">\n<p data-start=\"9861\" data-end=\"9959\">Setting an overly ambitious scope (everything and anything) and making the project unaffordable.<\/p>\n<\/li>\n<li data-start=\"9960\" data-end=\"10025\">\n<p data-start=\"9962\" data-end=\"10025\">Leave documentation and evidence until the day before the audit.<\/p>\n<\/li>\n<li data-start=\"10026\" data-end=\"10107\">\n<p data-start=\"10028\" data-end=\"10107\">Viewing TISAX as a one-off event rather than a <strong data-start=\"10076\" data-end=\"10106\">cycle of continuous improvement<\/strong>.<\/p>\n<\/li>\n<\/ul>\n<h2 data-start=\"10114\" data-end=\"10179\">6. How iCompliance can support your TISAX implementation<\/h2>\n<p data-start=\"10181\" data-end=\"10309\">The implementation of TISAX requires <strong data-start=\"10212\" data-end=\"10249\">coordination, experience, and method<\/strong>. iCompliance can provide support on several fronts, namely: <\/p>\n<ul data-start=\"10311\" data-end=\"10805\">\n<li data-start=\"10311\" data-end=\"10368\">\n<p data-start=\"10313\" data-end=\"10368\">TISAX\/ISO 27001 <strong data-start=\"10313\" data-end=\"10333\">gap assessment<\/strong> vs current situation;<\/p>\n<\/li>\n<li data-start=\"10369\" data-end=\"10420\">\n<p data-start=\"10371\" data-end=\"10420\">definition of <strong data-start=\"10384\" data-end=\"10419\">scope and evaluation objectives<\/strong>;<\/p>\n<\/li>\n<li data-start=\"10421\" data-end=\"10490\">\n<p data-start=\"10423\" data-end=\"10490\">design and implementation of <strong data-start=\"10450\" data-end=\"10489\">policies, procedures and records<\/strong>;<\/p>\n<\/li>\n<li data-start=\"10491\" data-end=\"10581\">\n<p data-start=\"10493\" data-end=\"10581\">integration with <strong data-start=\"10522\" data-end=\"10550\">GDPR<\/strong> requirements <strong>and data protection<\/strong> (in conjunction with <a href=\"https:\/\/iPrivacy.eu\" target=\"_blank\" rel=\"noopener\">iPrivacy.eu<\/a>);<\/p>\n<\/li>\n<li data-start=\"10582\" data-end=\"10677\">\n<p data-start=\"10584\" data-end=\"10677\">preparation of the organisation for the audit (simulation of interviews, review of evidence);<\/p>\n<\/li>\n<li data-start=\"10678\" data-end=\"10805\">\n<p data-start=\"10680\" data-end=\"10805\">use of platforms such as <a href=\"https:\/\/iComply.pt\" target=\"_blank\" rel=\"noopener\">iComply.pt<\/a> to manage tasks, risks, corrective actions, and evidence in a centralised manner.<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"10807\" data-end=\"11018\">If you are assessing the need to obtain a <strong data-start=\"10851\" data-end=\"10866\">TISAX label<\/strong> or already have specific customer requirements, we can help you structure a <strong data-start=\"10944\" data-end=\"11017\">phased implementation plan that is realistic and aligned with your business<\/strong>.<\/p>\n<h2 data-start=\"11025\" data-end=\"11046\">7. Next steps<\/h2>\n<p data-start=\"11048\" data-end=\"11065\">If your company:<\/p>\n<ul data-start=\"11067\" data-end=\"11248\">\n<li data-start=\"11067\" data-end=\"11110\">\n<p data-start=\"11069\" data-end=\"11110\">works in the automotive sector (or wants to enter it);<\/p>\n<\/li>\n<li data-start=\"11111\" data-end=\"11177\">\n<p data-start=\"11113\" data-end=\"11177\">receives requests for the &#8220;TISAX label&#8221; from OEMs or major suppliers;<\/p>\n<\/li>\n<li data-start=\"11178\" data-end=\"11248\">\n<p data-start=\"11180\" data-end=\"11248\">or you want to strengthen the credibility of your information security,<\/p>\n<\/li>\n<\/ul>\n<p data-start=\"11250\" data-end=\"11283\">so it makes sense to <strong data-start=\"11268\" data-end=\"11282\">start now<\/strong>:<\/p>\n<ol data-start=\"11285\" data-end=\"11462\">\n<li data-start=\"11285\" data-end=\"11341\">\n<p data-start=\"11288\" data-end=\"11341\">Identify customer requirements and likely scope;<\/p>\n<\/li>\n<li data-start=\"11342\" data-end=\"11407\">\n<p data-start=\"11345\" data-end=\"11407\">Perform an <strong data-start=\"11357\" data-end=\"11380\">initial diagnosis<\/strong> in accordance with VDA ISA\/ISO 27001;<\/p>\n<\/li>\n<li data-start=\"11408\" data-end=\"11462\">\n<p data-start=\"11411\" data-end=\"11462\">Define a TISAX plan for the next 6\u201312 months.<\/p>\n<\/li>\n<\/ol>\n<p data-start=\"12137\" data-end=\"12304\">To help you get started, download a <strong data-start=\"12181\" data-end=\"12226\">summary checklist for TISAX implementation<\/strong> in a format you can use as a PDF. To do so, request it below in the comments section of this article.<\/p>\n<p data-start=\"12137\" data-end=\"12304\">\n","protected":false},"excerpt":{"rendered":"<p>Implementing TISAX in your organisation: a practical guide for automotive suppliers Pressure from car manufacturers and major integrators to strengthen information security has led TISAX (Trusted Information Security Assessment Exchange) to become practically a &#8220;ticket of entry&#8221; into the European automotive supply chain. For many Portuguese companies, the question is no longer &#8220;if&#8221; they will [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2397,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1955","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sem-categoria"],"_links":{"self":[{"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/posts\/1955","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/comments?post=1955"}],"version-history":[{"count":4,"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/posts\/1955\/revisions"}],"predecessor-version":[{"id":2426,"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/posts\/1955\/revisions\/2426"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/media\/2397"}],"wp:attachment":[{"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/media?parent=1955"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/categories?post=1955"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icompliance.eu\/en\/wp-json\/wp\/v2\/tags?post=1955"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}