Why information security matters in the automotive supply chain
The automotive industry generates and exchanges large amounts of data throughout design, testing, validation, approval and production. Sensitive information includes component and system development projects, manufacturing processes and production-network data.
Automotive suppliers need to identify and reduce information-security risks and recover effectively from incidents. TISAX provides an industry mechanism for assessing and sharing evidence of information-security capability.
What is TISAX?
TISAX stands for Trusted Information Security Assessment Exchange.
TISAX is an assessment and information-exchange mechanism that enables participants to share recognised assessment results. It supports systematic assessment of the protection of sensitive customer information and supplier information security using VDA ISA.
TISAX labels are normally valid for three years from the closing meeting of the initial assessment. Renewal requires a new assessment. This is not a requirement for continuous assessment over three years, and a TISAX label is not a conventional management-system certificate.
VDA ISA is the information-security assessment catalogue used by TISAX. It draws on ISO/IEC 27001 and related information-security practices, with requirements tailored to automotive needs. Confirm the applicable ISA version and assessment objectives.
Background and development
The original article records the December 2018 VDA ISA 4.1.0 edition as a historical milestone; it is not the current edition to use for a new assessment.
TISAX establishes a common assessment and exchange mechanism for the automotive industry. The ENX Association governs the programme, approves audit providers and monitors assessment quality.
The ENX Association was established in 2000 as a non-profit automotive-industry association. Its activities support trusted cooperation and cross-company, cross-border information exchange.
Who uses TISAX?
Automotive OEMs and other customers may require specific TISAX assessment objectives and labels from suppliers. Confirm the contractual requirement, scope and relevant locations with the customer.
The original article cited over 3,000 participants and almost 6,000 registered sites. These are historical figures, not current programme totals. Participants include component manufacturers, technology providers and other organisations serving automotive customers.
Benefits of TISAX
Reduce repeated assessments by sharing results through the TISAX platform with authorised partners.
Save time and resources where customers accept the relevant shared assessment results.
Support relationships with existing suppliers.
Support new business opportunities through a recognised automotive-industry assessment mechanism.
Clarify the assessment scope and obtain comparable provider quotations to support planning; TISAX does not guarantee a uniform assessment price.
Apply a common information-security assessment approach in the automotive industry.
Help manufacturers and suppliers coordinate assessment effort and resources.
Identify improvement needs through assessment of information-security controls.
Discuss TISAX consulting and training with ITVC
Send your requirements so ITVC can advise on the service scope and provide a suitable quotation.