Frameworks / TISAX - Trusted Information Security Assessment Exchange / TISAX-TECH-03 TISAX - Trusted Information Security Assessment Exchange
Technical and Operational Security
TISAX - Trusted Information Security Assessment Exchange TISAX-TECH-03: Operations and Communications Security Implement operational procedures, change management, capacity management, malware protection, backup, logging, and network security controls.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 231 controls across 63 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
ASD37-06 Email content filtering (Excellent) ASD37-12 Antivirus software with heuristics (Very Good) ASD37-16 Antivirus software with signatures (Limited) ASD37-20 Multi-factor authentication (Essential) ASD37-22 Network segmentation (Excellent) ASD37-25 Software firewall - inbound (Very Good) ASD37-34 Regular backups (Essential) ASD37-35 Business continuity and disaster recovery plans (Very Good) ASD37-36 System recovery capabilities (Very Good) BSI-24 Configuration change control BSI-28 Audit event logging and storage BSI-29 Audit record review and analysis BSI-31 Audit log protection and retention NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability SOC2-A1.3 Recovery plan procedures support system recovery from failures SOC2-CC8.1 Change management processes are in place CPG-1.D Revoking Credentials for Departing Employees CPG-8.A Network Segmentation 4.4.8 Business Continuity and Recovery DIQ-1 Data Integration and Interoperability CJIS-10 System and Information Integrity ISO9001-18 Cl. 6.3 Planning of changes - innovation and change management for the quality management system CPSC-CS.1 Network Security for Connected Products CYB-5 Cyber Incident Response Plan Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Technical and Operational Security Query this from an agent The graph holds this control, the 231 it maps to, and the evidence behind each claim, over MCP and REST.