Shadow AI is already using your data. Get the complimentary Gartner® report. Read the report

TISAX Compliance

PKWARE

By PKWAREProductivity Protected

Share on social media

Download

Information security mandates like TISAX are complex and multi-faceted, requiring the efforts of multiple departments within an organization, along with multiple vendors, partners, and advisors. No single technology solution will make your company TISAX-compliant. Wherever you are on your TISAX compliance journey, PKWARE can help.

Where TISAX Comes From

The German Association of the Automotive Industry, the VDA, has worked on an industry information security standard since 2003. Its Information Security Assessment questionnaire is now the established framework companies use to assess their own maturity and to build trust between manufacturers, suppliers, service providers and consumers.

The reason it exists is practical. An industry with deep, shared supply chains needs a common answer to the question of how well a partner protects information, and bilateral audits do not scale.

What the Assessment Covers

The current VDA ISA consists of 67 controls written as questions, examining organizational governance, risk management practice and technical measures.

They span three areas: information security, prototype protection and personal data protection. Prototype protection is the one with no equivalent in most other frameworks, and it reflects an industry where a design leak before launch is as damaging as a data breach.

How TISAX Works

To avoid every company being audited repeatedly by every partner, the VDA established the Trusted Information Security Assessment Exchange and handed its operation to a neutral third party, the ENX Association.

Organizations register online, select an audit provider accredited by ENX, complete an assessment and exchange the official result with other participants. Each assessment is valid for three years, which is what makes the shared model cheaper than the bilateral one it replaced.

How Widely It Is Used

More than 2,800 companies worldwide have registered with TISAX and more than 2,600 assessments have been performed.

The VDA has reported more than 25,000 improvements to information security achieved across participating companies in a two-year period, which is the argument for a shared standard rather than a set of private ones.

Who Needs It

Any organization exchanging sensitive information with an automotive manufacturer or a tier supplier is likely to be asked for a TISAX result, regardless of sector or location.

That is the characteristic worth noting. TISAX arrives through a commercial relationship rather than through jurisdiction, so a supplier with no German operations and no automotive self-description can still find it contractually required.

It Keeps Moving With the Technology

The questionnaire is revised periodically to reflect changing technology and regulation, from cloud computing and the Internet of Things through to privacy law such as GDPR.

A compliance approach built around the specific controls of one version therefore ages badly. Knowing what sensitive data exists, where it is and what protects it answers the current questionnaire and the next one, because that is what every version of it is ultimately asking.

Preparing for an Assessment

Three pieces of evidence carry most of the technical section. An inventory of what sensitive data exists and where, a record of the protection applied to it, and proof that both are maintained continuously rather than produced for the audit.

Organizations that already hold those answer the questionnaire from existing records. Those that do not spend the preparation period building the inventory, which is the work the assessment was asking about in the first place.

PKWARE

PKWARE

Productivity Protected

PKWARE has been securing sensitive data for over 40 years. We’ve earned the trust of 21 of the 25 largest banks in the U.S. Our team delivers modern, data-centric security solutions organizations can rely on.