Frameworks / TISAX - Trusted Information Security Assessment Exchange / TISAX-IS-03 TISAX - Trusted Information Security Assessment Exchange
People and Third Parties
TISAX - Trusted Information Security Assessment Exchange TISAX-IS-03: Third-Party Risk Management Information security requirements for suppliers and service providers. Assessment of third-party security posture. Contractual security requirements. Supply chain risk management for automotive data.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 177 controls across 65 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CPS230-16 Internal Audit Review of the Business Continuity Plan CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-37 Service Provider Management Policy CPS230-46 Ongoing Risk Management of Each Material Arrangement CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing 27557-1 Scope 27557-3 Terms and definitions 27557-6.4 Privacy risk treatment 27557-6.6 Recording and reporting 27557-7.3 Risk-based privacy program implementation NIST-CSF-GV.RM-03 Cybersecurity risk management activities and outcomes are included in enterprise risk management processes NIST-CSF-GV.RM-04 Strategic direction that describes appropriate risk response options is established and communicated NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition AEO-2 Demonstrated Compliance with Customs Requirements AEO-4 Financial Viability P1-S2 Risk-Management Systems P2-S1 Partnership ISO-20400-4.5 Key considerations for sustainable procurement ISO-20400-7.3 Supplier selection ISO-20400-7.4 Contract management and review ISO-20400-7.5 Reviewing and learning ISO23894-5.1 Leadership and Commitment ISO23894-5.2 AI Risk Management Integration ISO23894-5.5 Framework Evaluation ISO23894-A.6 AI System Security ISO27003-4.2 Understanding the needs and expectations of interested parties ISO27003-6.1 Actions to address risks and opportunities ISO27003-8.1 Operational planning and control ISO27003-8.3 Information security risk treatment ISO27019-21 Supply chain risk management for critical components ISO27019-22 Configuration management for OT systems ISO27019-23 Change management procedures ISO27019-24 Vulnerability assessment for critical systems SASB-BMI-3 Supply Chain Management SASB-LG-2 Systemic Risk Management SASB-LG-3 Critical Incident Risk Management SASB-LG-5 Systemic Risk Management SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain SOCI-S30AC Obligation to adopt a CIRMP SOCI-S30AD Compliance with CIRMP SOCI-S30AE Annual review of CIRMP SII-P2-09 Outsourcing Requirements SII-P2-11 Remuneration Policy SII-P2-12 Written Policies SII-P3-06 SFCR Section B: System of Governance API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures IS.D.OR.210 Information Security Risk Treatment IS.I.OR.210 Information Security Risk Treatment IS.I.OR.220 Information Security Risk Management FFIEC-03 Risk appetite and tolerance for IT risk FFIEC-18 Ongoing monitoring and assessment FFIEC-20 Exit strategy and transition planning 60601-1.4.1 General requirements 60601-1.4.2 Risk management process 60601-1.5.1 General requirements for testing IEC62304-4.1 Quality Management System IEC62304-5.1 Software Development Planning IEC62304-7.4 Risk Management of Software Changes IEC62443-21 Supply chain risk management for critical components IEC62443-22 Configuration management for OT systems IEC62443-23 Change management procedures A.1 Point-of-Care Testing Additional Requirements ISO-15189-5.6 Risk management ISO-15189-6.8 Externally provided products and services ISO28001-PC-03 Supply Chain Incident Reporting ISO28001-PC-04 Supply Chain Continuity Planning ISO28001-SA-04 Security Risk Treatment Planning PCI-P2PE-16 Due diligence and onboarding PCI-P2PE-18 Ongoing monitoring and assessment PCI-P2PE-19 Concentration risk management PCI-PIN-16 Due diligence and onboarding PCI-PIN-18 Ongoing monitoring and assessment PCI-PIN-19 Concentration risk management PCI-SSF-03 Risk appetite and tolerance for IT risk PCI-SSF-16 Due diligence and onboarding PCI-SSF-17 Contractual security requirements RMI-DD-3 Red Flag Review RMI-MS-2 Cobalt Standard RMI-RMAP-2 Risk-Based Audit Approach SOC-CY-DC1 Nature of Business and Operations SOC-CY-DC3 Cybersecurity Risk Management Objectives SOC-CY-DC4 Governance Structure CPS234-16 Assessment of Related Party and Third Party Capability CPS234-20 Information Asset Classification AS9100D-8.1 Operational Planning and Control AS9100D-8.4 Control of Externally Provided Processes, Products, Services BS65000-RM-01 Resilience Journey BS65000-RM-02 Integrated Approach CPG-6.A Vendor and Supplier Incident Reporting CPG-6.B Supply Chain Incident Reporting CAT-D1-2 Risk management CAT-ML-2 Evolving ICP-16 Enterprise Risk Management for Solvency Purposes ICP-8 Risk Management and Internal Controls ISMSP-MS-02 Risk Management ISMSP-PI-03 Third-Party Provision and Outsourcing CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records AMLCTF-82 Part A Compliance SPS220-28 Annual Board Risk Management Declaration ACQ.4 Supplier Monitoring Mat 03 Responsible Sourcing of Materials CJIS-19 Supply Chain Risk Management ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18) ISO22316-14 Supply chain continuity ISO-22320-4.3 Risk-based approach ISO-26000-6.6 Fair operating practices ISO-41001-8.4 Control of outsourced processes and services ISO-50001-8.3 Procurement 27010-15.1 Incident Management 27011-5.6 Supplier relationships and telecom supply chain ISO22317-14 Supply chain continuity ISO22318-14 Supply chain continuity PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets SSAE18-CC9.2 CC9.2 - Vendor and Business Partner Risk Management AIGF-1.1 Risk Management and Internal Controls IM8-TPM.4 Supply Chain Risk Management GT-3 Supply Chain Compromise TSSR-SEC-3 National Security Risk Management CRM-3 Risk Management Framework UKAI-1 Risk-Based Approach and Pro-Innovation Principles SEMD-PS-3 Supply Chain Security UK-TSA-NET-03 Supply Chain Security Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in People and Third Parties Query this from an agent The graph holds this control, the 177 it maps to, and the evidence behind each claim, over MCP and REST.