TISAX - Trusted Information Security Assessment Exchange
ISA

TISAX - Trusted Information Security Assessment Exchange TISAXASS-2: ISA Catalog Implementation

Per TISAX VDA ISA Catalog: implement controls aligned to ISO 27001 + automotive specifics including prototype protection + supplier data + connected vehicle.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 201 controls across 65 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 9 controls

  • ISO27043-06 Asset inventory and ownership
  • ISO27043-08 Information classification and labeling
  • ISO27043-10 Media management and disposal
  • ISO27043-11 Access control policy and enforcement
  • ISO27043-14 Privileged access management
  • ISO27043-15 Access review and recertification
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 9 controls

  • ISO21434-07 Acceptable use of assets
  • ISO21434-08 Information classification and labeling
  • ISO21434-09 Asset handling procedures
  • ISO21434-12 User access management and provisioning
  • ISO21434-14 Privileged access management
  • ISO21434-15 Access review and recertification
  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-19 Certificate management

NIST SP 800-53 Rev 5 · 9 controls

ISO 27799:2025 · 5 controls

  • ISO27799-01 ePHI access controls and authorization
  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-08 Information access management
  • ISO27799-16 Transmission security and encryption
  • ISO27799-17 Facility access controls

ISO/IEC 27010:2015 · 5 controls

  • 27010-10.1 Cryptographic Protection
  • 27010-11.1 Physical Protection
  • 27010-8.1 Membership Onboarding
  • 27010-9.1 Access Control to Shared Information
  • 27010-9.2 Authentication of Sources

ISO/IEC 27011:2024 · 5 controls

  • 27011-5.3 Segregation of duties
  • 27011-7.1 Physical security perimeters
  • 27011-7.3 Equipment protection
  • 27011-8.1 User Endpoint Devices
  • 27011-8.3 Cryptography and key management
  • AWWA-2.1 User Access Management
  • AWWA-2.4 Physical Access Controls
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

BSI IT-Grundschutz · 4 controls

  • BSI-03 Multi-factor authentication requirements
  • BSI-04 Remote access controls
  • BSI-05 Wireless access restrictions
  • BSI-08 Cryptographic protection of data
  • QRCM-1.1 Cryptographic Asset Inventory
  • QRCM-1.2 Quantum-Vulnerable Identification
  • QRCM-3.1 Hybrid Solution Deployment (2025-2030)
  • QRCM-4.2 TLS 1.3 Adoption

API 1164 · 3 controls

  • API1164-06 Access Control
  • API1164-07 Remote Access
  • API1164-09 Patch and Vulnerability Management
  • CJIS-14 Physical Protection
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

IEC 62443 · 3 controls

  • IEC62443-07 Personnel risk assessment
  • IEC62443-08 Electronic access perimeter management
  • IEC62443-10 Revocation of access procedures

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

ISO/IEC 27019:2024 · 3 controls

  • ISO27019-07 Personnel risk assessment
  • ISO27019-08 Electronic access perimeter management
  • ISO27019-10 Revocation of access procedures

NIST SP 1800-32 · 3 controls

South Korea ISMS-P · 3 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-02 Encryption Implementation

APPI · 2 controls

  • APPI-A26 Report of Leakage to the Commission and Notification to the Person
  • APPI-A34 Request for Correction, Addition or Deletion

Bahrain PDPL · 2 controls

  • DSO-2 Data Security
  • DSO-3 Data Access Management
  • CAT-D3-1 Preventative controls
  • CAT-D4-3 Third-party access controls
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • UAE-PDPL-Art.6_7 Sensitive personal data and children's data (UAE PDPL Articles 6-7)
  • 62351-8 Role-based access control (RBAC)
  • 62351-9 Cyber security key management

ISO/IEC 27400:2022 · 2 controls

  • 27400-5.2 IoT Risk Assessment
  • 27400-6.2 Device Identity and Authentication

SOC 2 · 2 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC-CY-C2 Encryption and Data Protection
  • SOC-CY-S1 Logical and Physical Access Controls

Saudi Arabia PDPL · 2 controls

  • SA-PDPL-13 Encryption of personal data
  • SA-PDPL-15 Access control for personal data
  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.2 Access Control

Taiwan PDPA · 2 controls

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TAIWAN-3 Data Subject Rights
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management
  • SEMD-PS-1 Critical Infrastructure Protection
  • SEMD-PS-2 Site Security Measures
  • 58.43 Animal Care Facilities
  • ASD37-17 TLS encryption between email servers (Limited)
  • AT-DSG-6 Sections 12-13 - Image processing (video surveillance/CCTV)
  • CA-ITSG33-SC-01 Security Control Catalogue
  • FFIEC-09 Encryption and key management
  • ICAO-ANX17-Chap2-ThreatAssessment-RiskManagement-Cyber-GASeP ICAO Annex 17 Chapter 2 - Threat Assessment + Risk Management + Cyber Threats to Critical Aviation Systems (Amendment 17/18)
  • ISO28001-PS-01 Facility Security
  • ISO20000-15 Access management for services
  • 29115-7.4 Level of Assurance 4 (LoA4)

ITIL 4 · 1 control

  • ITIL4-15 Access management for services
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk

NIST SP 800-190 · 1 control

PCI P2PE · 1 control

  • PCI-P2PE-09 Encryption and key management

PCI PIN Security · 1 control

  • PCI-PIN-09 Encryption and key management

PCI SSF · 1 control

  • PCI-SSF-09 Encryption and key management
  • SSAE18-CC6.4 CC6.4 - Physical Access Restrictions
  • SBD-DEV-04 Phishing-Resistant Authentication
  • SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • TEXASTDPSA-2 Consumer Rights

Turkey KVKK · 1 control

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • UKGAMBLE-4 Resilience and Incident Response
  • CPSC-CS.2 Authentication and Access Controls
  • USSDWA-2 Cybersecurity Practices (Assessment, Access, Network, IR)
  • USMTSA-1 Facility Security Assessment and Plan

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 201 it maps to, and the evidence behind each claim, over MCP and REST.