TISAX - Trusted Information Security Assessment Exchange
Technical and Operational Security

TISAX - Trusted Information Security Assessment Exchange TISAX-TECH-03: Operations and Communications Security

Implement operational procedures, change management, capacity management, malware protection, backup, logging, and network security controls.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 216 controls across 54 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

API 1164 · 6 controls

  • API1164-12 Incident Response
  • API1164-13 Business Continuity and Recovery
  • API1164-17 Wireless and Field Communications
  • API1164-18 Field Device Security
  • API1164-19 Safety Instrumented Systems Interface
  • API1164-23 Change management procedures

IEC 62443 · 6 controls

  • IEC62443-12 Malware prevention for operational systems
  • IEC62443-13 Network security monitoring
  • IEC62443-16 Incident response plan for operational disruptions
  • IEC62443-17 Recovery plan for critical systems
  • IEC62443-20 Exercises and drills for OT incidents
  • IEC62443-23 Change management procedures

ISO/IEC 27019:2024 · 6 controls

  • ISO27019-12 Malware prevention for operational systems
  • ISO27019-13 Network security monitoring
  • ISO27019-16 Incident response plan for operational disruptions
  • ISO27019-18 Reporting obligations to authorities
  • ISO27019-20 Exercises and drills for OT incidents
  • ISO27019-23 Change management procedures

NIST SP 1800-32 · 6 controls

NIST SP 800-53 Rev 5 · 6 controls

ISO/IEC 27011:2024 · 5 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation
  • 27011-8.4 Logging and monitoring
  • 27011-8.5 Vulnerability and malware management
  • 27011-8.6 Data protection and backup
  • SSAE18-A1.2 A1.2 - Environmental Protections and Recovery
  • SSAE18-A1.3 A1.3 - Recovery Plan Testing
  • SSAE18-CC3.4 CC3.4 - COSO Principle 9: Change Management
  • SSAE18-CC7.5 CC7.5 - Incident Recovery
  • SSAE18-CC8.1 CC8.1 - Infrastructure and Software Change Management

BSI IT-Grundschutz · 4 controls

  • BSI-24 Configuration change control
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

ISO/IEC 27043:2015 · 4 controls

  • ISO27043-22 Protection from malware
  • ISO27043-23 Backup and recovery procedures
  • ISO27043-24 Logging and monitoring
  • ISO27043-27 Network security management

ISO/SAE 21434 · 4 controls

  • ISO21434-22 Protection from malware
  • ISO21434-23 Backup and recovery procedures
  • ISO21434-24 Logging and monitoring
  • ISO21434-27 Network security management

NIST SP 800-190 · 4 controls

  • PICERL-C2 System Backup
  • PICERL-E1 Threat Removal
  • PICERL-R1 System Restoration
  • PICERL-R2 Security Verification

South Korea ISMS-P · 4 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-PI-06 Personal Information Destruction
  • ISMSP-SYS-03 Security Monitoring and Log Management
  • ISMSP-SYS-06 Business Continuity and Disaster Recovery
  • AWWA-3.1 Network Segmentation
  • AWWA-4.1 Malware Protection
  • AWWA-4.4 Audit Logging and Monitoring

ISO/IEC 27031:2011 · 3 controls

  • 27031-8.1 Exercising and Testing
  • 27031-8.2 Maintaining IRBC
  • 27031-9.3 Management Review
  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

SOC 2 · 3 controls

  • SOC2-A1.2 A1.2 Environmental protection, backup and recovery infrastructure
  • SOC2-A1.3 A1.3 Testing recovery plan procedures
  • SOC2-CC8.1 CC8.1 Managing changes to procedures, software, data and infrastructure
  • IM8-RES.2 Disaster Recovery
  • IM8-RES.4 Resilience Testing
  • IM8-SEC.3 Network Security
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-8.A Network Segmentation
  • CAT-D3-1 Preventative controls
  • CAT-D3-2 Detective controls
  • FFIEC-06 Network security and segmentation
  • FFIEC-12 Disaster recovery procedures
  • IEC62304-8.2 Change Control
  • IEC62304-9.4 Use Change Control Process

ISO 22316 · 2 controls

  • ISO22316-08 Recovery time and point objectives
  • ISO22316-12 Recovery strategy for critical activities

ISO/IEC 27010:2015 · 2 controls

  • 27010-12.2 Protection from malware
  • 27010-13.1 Communications Security

ISO/TS 22317:2021 · 2 controls

  • ISO22317-08 Recovery time and point objectives
  • ISO22317-12 Recovery strategy for critical activities

ISO/TS 22318:2021 · 2 controls

  • ISO22318-08 Recovery time and point objectives
  • ISO22318-12 Recovery strategy for critical activities
  • NFPA1600-5.3 Resource Needs Assessment
  • NFPA1600-6.4 Continuity and Recovery

PCI P2PE · 2 controls

  • PCI-P2PE-06 Network security and segmentation
  • PCI-P2PE-12 Disaster recovery procedures

PCI PIN Security · 2 controls

  • PCI-PIN-06 Network security and segmentation
  • PCI-PIN-12 Disaster recovery procedures

PCI SSF · 2 controls

  • PCI-SSF-06 Network security and segmentation
  • PCI-SSF-12 Disaster recovery procedures
  • SOC-CY-A2 Disaster Recovery
  • SOC-CY-S3 Change Management
  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability
  • CJIS-10 System and Information Integrity

FedRAMP Rev 5 · 1 control

  • FEDRAMP-CP-9 System Backup
  • 62351-14 Cyber security event logging

ISO 22320:2018 · 1 control

  • ISO-22320-5.2 Incident management process
  • ISO-26262-8-8 Change management

ISO 27799:2025 · 1 control

  • ISO27799-05 Audit trail for ePHI access
  • ISO28001-PS-01 Facility Security

ISO 30401 · 1 control

  • ISO30401-18 Innovation and change management
  • ISO20000-06 Change management processes
  • ISO-25012-4.11 Traceability

ITIL 4 · 1 control

  • ITIL4-06 Change management processes

SASB Standards · 1 control

  • SASB-BMI-5 Physical Impacts of Climate Change
  • CPSC-CS.1 Network Security for Connected Products

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical and Operational Security

Query this from an agent

The graph holds this control, the 216 it maps to, and the evidence behind each claim, over MCP and REST.