What is TISAX?
TISAX (Trusted Information Security Assessment Exchange) is the automotive sector's information-security passport, managed by the ENX Association. Tier-1 and Tier-2 suppliers undergo TISAX assessments at Assessment Levels (AL1, AL2, AL3) corresponding to data-sensitivity tiers. The technical-controls layer derives from ISO 27001 Annex A. OEMs require TISAX assessment evidence from every supplier.
The longer answer.
TISAX assessments use the VDA ISA questionnaire, which is built on ISO 27001. Assessment Level 1 is a self-assessment, Level 2 is a remote assessment and Level 3 is on-site. Most OEMs require AL2, AL3 applies where data is highly confidential, and results are valid for three years.
The technical sections of VDA ISA, such as system security, cryptography and network security, are where configuration evidence applies. CISGuard does not map VDA ISA directly; its ISO 27001 report covers the related Annex A controls, which can be presented to the assessor as supporting evidence.
More questions on Frameworks?
Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.