TISAX - Trusted Information Security Assessment Exchange
Technical and Operational Security

TISAX - Trusted Information Security Assessment Exchange TISAX-TECH-03: Operations and Communications Security

Implement operational procedures, change management, capacity management, malware protection, backup, logging, and network security controls.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 231 controls across 63 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

API 1164 · 6 controls

IEC 62443 · 6 controls

ISO 27019 · 6 controls

NIST SP 1800-32 · 6 controls

NIST SP 800-53 Rev 5 · 6 controls

ISO/IEC 27011:2024 · 5 controls

BSI IT-Grundschutz · 4 controls

  • BSI-24 Configuration change control
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

ISO 27017 · 4 controls

ISO 27018 · 4 controls

ISO 27043 · 4 controls

ISO/SAE 21434 · 4 controls

NIST SP 800-190 · 4 controls

South Korea ISMS-P · 4 controls

ISO/IEC 27031:2011 · 3 controls

  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

SOC 2 · 3 controls

  • SOC2-A1.2 Environmental protections, data backups, and recovery infrastructure support availability
  • SOC2-A1.3 Recovery plan procedures support system recovery from failures
  • SOC2-CC8.1 Change management processes are in place
  • CPG-1.D Revoking Credentials for Departing Employees
  • CPG-8.A Network Segmentation

ISO 22316 · 2 controls

ISO 22317 · 2 controls

ISO 22318 · 2 controls

ISO/IEC 27010:2015 · 2 controls

PCI P2PE · 2 controls

PCI PIN Security · 2 controls

PCI SSF · 2 controls

  • 4.4.8 Business Continuity and Recovery
  • DIQ-1 Data Integration and Interoperability
  • CJIS-10 System and Information Integrity

ISO 13485 · 1 control

ISO 19011 · 1 control

ISO 20000-1 · 1 control

ISO 22320:2018 · 1 control

ISO 27799 · 1 control

ISO 30401 · 1 control

ISO 37001 · 1 control

ISO 37301 · 1 control

ISO 55001 · 1 control

ISO 9001 · 1 control

  • ISO9001-18 Cl. 6.3 Planning of changes - innovation and change management for the quality management system

ITIL 4 · 1 control

SASB Standards · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technical and Operational Security

Query this from an agent

The graph holds this control, the 231 it maps to, and the evidence behind each claim, over MCP and REST.