TISAX - Trusted Information Security Assessment Exchange
Assessment

TISAX - Trusted Information Security Assessment Exchange TISAXASS-1: Assessment Levels and Process

Per TISAX VDA ISA: assessment levels + process. Requirements include (a) Assessment Levels AL1 + AL2 + AL3 per scope + risk + (b) Assessment Process via TISAX-approved audit provider + (c) Results Exchange via ENX Portal + (d) cooperate with auditor.

What else in your programme already covers this

This control maps to 122 controls across 70 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27003:2017 · 4 controls

  • 3.1 Physical Security
  • 3.16 System and Services Acquisition
  • 3.17 Supply Chain Risk Management
  • 3.5 Securely Dispose of Data

API 1164 · 3 controls

  • AEO-2 Demonstrated Compliance with Customs Requirements
  • AEO-4 Financial Viability
  • P2-S1 Partnership
  • 1.1 SWIFT Environment Protection
  • 3.1 Physical Security
  • 3.5 Securely Dispose of Data

IEC 62443 · 3 controls

ISO 27019 · 3 controls

ISO 9001 · 3 controls

  • NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders
  • NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained
  • NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition

NIST SP 1800-32 · 3 controls

NIST SP 800-53 Rev 5 · 3 controls

Solvency II · 3 controls

  • CPS230-27 Identification and Escalation of Incidents and Near Misses
  • CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing
  • AS9100D-10.2 Nonconformity and Corrective Action
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • CPG-6.A Vendor and Supplier Incident Reporting
  • CPG-6.B Supply Chain Incident Reporting
  • 2.5.2 Verification Activities
  • 2.7.2 Food Fraud Plan

South Korea ISMS-P · 2 controls

  • CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records
  • AS9100D-8.4 Control of Externally Provided Processes, Products, Services
  • Clause 3 Suppliers and service providers
  • CJIS-19 Supply Chain Risk Management

ISO 19011 · 1 control

ISO 22000 · 1 control

ISO 22316 · 1 control

ISO 22317 · 1 control

ISO 22318 · 1 control

ISO 26000:2010 · 1 control

ISO 27005 · 1 control

ISO 30401 · 1 control

ISO 31000 · 1 control

ISO 37001 · 1 control

ISO 37301 · 1 control

ISO 45001 · 1 control

ISO 55001 · 1 control

ISO 56002 · 1 control

ISO/IEC 23894:2023 · 1 control

ISO/IEC 27010:2015 · 1 control

ISO/IEC 27011:2024 · 1 control

  • 27011-5.6 Supplier relationships and telecom supply chain

ISO/IEC 27014:2020 · 1 control

  • PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets

SASB Standards · 1 control

  • UKOPRES-5 Third-Party Risk, Concentration Risk
  • VPSHR-3 Implementation Guidance and Reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 122 it maps to, and the evidence behind each claim, over MCP and REST.