TISAX - Trusted Information Security Assessment Exchange
Technical and Operational Security

TISAX - Trusted Information Security Assessment Exchange TISAX-TECH-01: Access Control and Identity Management

Implement access control policies, user access management, privileged access controls, and secure authentication mechanisms for all information systems.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 132 controls across 43 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 7 controls

  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-2.2 Authentication Mechanisms
  • AWWA-2.3 Account Management
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-23 Protect authentication credentials (Excellent)

BSI IT-Grundschutz · 3 controls

  • BSI-01 Account management and provisioning
  • BSI-02 Access enforcement and least privilege
  • BSI-03 Multi-factor authentication requirements

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-12 User access management and provisioning
  • ISO27043-13 Authentication and password management
  • ISO27043-14 Privileged access management
  • 29115-11 Mapping other authentication schemes
  • 29115-12.1 Exchanging authentication results
  • 29115-12.2 Controls for mitigating threats

ISO/SAE 21434 · 3 controls

  • ISO21434-12 User access management and provisioning
  • ISO21434-13 Authentication and password management
  • ISO21434-14 Privileged access management
  • NIST-CSF-PR.AA-01 Identities and credentials for authorized users, services, and hardware are managed by the organization
  • NIST-CSF-PR.AA-02 Identities are proofed and bound to credentials based on the context of interactions
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

NIST SP 800-190 · 3 controls

South Korea ISMS-P · 3 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-02 User Account Management
  • ISMSP-AC-03 Authentication Mechanisms
  • OB-CX.3 Strong Customer Authentication
  • OB-DIR.1 Open Banking Directory
  • OB-SEC.4 Certificate Management

ISO 27799:2025 · 2 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-12 Unique user identification and authentication
  • BIPA-SEC5-1 Biometric Identifier Definition
  • BIPA-SEC5-2 Biometric Information Definition

SOC 2 · 2 controls

  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-SOC1-06 Transaction Processing Controls
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements
  • AMLCTF-35 Identity Verification Standard
  • DSO-3 Data Access Management
  • CAT-IRP-4 Organizational characteristics
  • 62351-8 Role-based access control (RBAC)

ISO/IEC 23837:2023 · 1 control

  • 23837-1.7.3 Authentication and classical post-processing

ISO/IEC 27010:2015 · 1 control

  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

ISO/IEC 27400:2022 · 1 control

  • 27400-6.1 Secure Device Design
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • UK-TSA-NET-02 Access Control and Authentication
  • ACE-CR-4 Cargo Release Authorization
  • CPSC-CS.2 Authentication and Access Controls
  • UGA-10 Sensitive Personal Data Prohibition
  • VP-2 Holder Binding

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical and Operational Security

Query this from an agent

The graph holds this control, the 132 it maps to, and the evidence behind each claim, over MCP and REST.