TISAX - Trusted Information Security Assessment Exchange
Prototype

TISAX - Trusted Information Security Assessment Exchange TISAXASS-3: Prototype Protection and Confidentiality

Per TISAX ISA: Prototype Protection including physical + IT controls for high-confidentiality prototypes + vehicle parts.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 262 controls across 68 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • CH-FADP-02 Principles of lawful processing
  • CH-FADP-04 Data subject access right
  • CH-FADP-05 Data accuracy and rectification
  • CH-FADP-19 Transparency and proactive information
  • CH-FADP-21 Data protection impact assessments
  • FADP-11 Duty to Inform (Article 19)
  • FADP-12 Right of Access (Article 25)
  • FADP-15 Data Breach Notification
  • FADP-16 FDPIC Independence and Functions
  • FADP-7 Data Protection Impact Assessment (Articles 9-10)
  • FADP-9 Data Protection Advisor (Articles 14-15)

GDPR · 8 controls

  • GDPR-Art.10 Processing of personal data relating to criminal convictions
  • GDPR-Art.11 Processing which does not require identification
  • GDPR-Art.15 Right of access by the data subject
  • GDPR-Art.19 Notification obligation regarding rectification, erasure or restriction
  • GDPR-Art.25 Data protection by design and by default
  • GDPR-Art.35 Data protection impact assessment
  • GDPR-Art.38 Position of the data protection officer
  • GDPR-Art.9 Processing of special categories of personal data
  • AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction
  • AT-DSG-11 Sections 42-45 - Data subject rights (law enforcement)
  • AT-DSG-12 Section 62 - Administrative penalties
  • AT-DSG-13 Section 36 - Scope of law enforcement processing
  • AT-DSG-14 Section 38 - Lawfulness of law enforcement processing
  • AT-DSG-7 Section 18 - Establishment of the Data Protection Authority
  • Standard 13 Nudge Techniques
  • Standard 14 Connected Toys and Devices
  • Standard 15 Online Tools
  • Standard 2 Data Protection Impact Assessments
  • Standard 5 Detrimental Use of Data
  • Standard 8 Data Minimisation

Bahrain PDPL · 5 controls

  • BB-DPA-1 Section 1 - Short Title
  • BB-DPA-14 Section 15 - Right to Data Portability
  • BB-DPA-16 Section 22 - General Principle for Transfers
  • BB-DPA-21 Sections 61-69 - Data Privacy Officer
  • BB-DPA-4 Section 4 - Principles Relating to Processing

Saudi Arabia PDPL · 5 controls

  • SA-PDPL-13 Encryption of personal data
  • SA-PDPL-15 Access control for personal data
  • SA-PDPL-19 Data protection officer designation
  • SA-PDPL-21 Data protection impact assessments
  • SA-PDPL-22 Privacy by design and default
  • AZ-DPA-12 Article 13 - Cross-border transfer
  • AZ-DPA-14 Article 16 - Liability for violations
  • AZ-DPA-15 Article 17 - Dispute resolution
  • AZ-DPA-6 Article 6 - State regulation in personal data protection

ISO/IEC 27011:2024 · 4 controls

  • 27011-5.2 Information Security Roles in Telecoms
  • 27011-6.3 Awareness and Training
  • 27011-8.4 Logging and monitoring
  • 27011-8.6 Data protection and backup

ISO/IEC 27400:2022 · 4 controls

  • 27400-5.4 Data and privacy risks
  • 27400-7.1 Network Security for IoT
  • 27400-7.3 Data minimization and purpose limitation
  • 27400-7.4 Data retention and deletion

NIST SP 800-190 · 4 controls

South Korea ISMS-P · 4 controls

  • ISMSP-PI-01 Personal Information Collection
  • ISMSP-PI-04 Cross-Border Transfer
  • ISMSP-SYS-02 Encryption Implementation
  • ISMSP-SYS-03 Security Monitoring and Log Management

APPI · 3 controls

  • APPI-A23 Security Control Measures
  • APPI-A24 Supervision of Employees
  • APPI-A33 Request for Disclosure of Retained Personal Data
  • APP-1 APP 1 - Open and transparent management of personal information
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-5 APP 5 - Notification of the collection of personal information

BSI IT-Grundschutz · 3 controls

  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention
  • UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10)
  • UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

ISO 27799:2025 · 3 controls

  • ISO27799-03 Minimum necessary standard enforcement
  • ISO27799-04 Patient data de-identification procedures
  • ISO27799-05 Audit trail for ePHI access

ISO/IEC 29100:2024 · 3 controls

  • 29100-6.10 Information security
  • 29100-6.5 Use, retention and disclosure limitation
  • 29100-6.9 Accountability

ISO/IEC 29134:2023 · 3 controls

  • 29134-1 Scope
  • 29134-3 Terms and definitions
  • 29134-9.1 PIA report structure

NIST SP 800-53 Rev 5 · 3 controls

SOC 2 · 3 controls

  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent
  • SWE-1 Scope and Purpose
  • SWE-11 Integritetsskyddsmyndigheten (IMY)
  • SWE-2 Relationship to GDPR
  • AWWA-3.4 Encryption and Data Protection
  • AWWA-4.4 Audit Logging and Monitoring
  • AL-DPA-12 International Data Transfers
  • AL-DPA-14 Direct Marketing
  • 27557-3 Terms and definitions
  • 27557-4.3 Individual impact consideration
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-4 Sensitive Data Processing Consent and Childrens Protections

SASB Standards · 2 controls

  • SASB-SC-1 Customer Privacy and Data Security
  • SASB-SOC-2 Customer Privacy
  • SOC-CY-C2 Encryption and Data Protection
  • SOC-CY-DC2 Nature of Sensitive Information
  • SSAE18-P1.1 P1.1 - Privacy Notice
  • SSAE18-P1.2 P1.2 - Choice and Consent
  • IM8-DAT.2 Data Protection
  • IM8-DAT.4 Data Retention and Disposal

Taiwan PDPA · 2 controls

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TAIWAN-3 Data Subject Rights
  • TRINIDAD-4 Security, Accuracy
  • TRINIDAD-5 Enforcement and Sanctions

Turkey KVKK · 2 controls

  • TURKEYKVKK-2 Information Notice and Data Subject Rights
  • TURKEYKVKK-3 Special Categories and Sensitive Data
  • USMCADIGITAL-1 Cross-Border Data Flows and Localisation
  • USMCADIGITAL-2 Personal Information Protection and Consumer Protection
  • VERMONTAICDA-3 Bias Testing, Discrimination Prevention, Transparency
  • VERMONTAICDA-4 Vermont AG Enforcement and Cure
  • VIETNAMCYBER-2 Prohibited Acts (Access, Interception, Forgery, Content)
  • VIETNAMCYBER-4 Incident Reporting and Cooperation

Vietnam PDPD · 2 controls

  • VIETNAMPDP-1 Scope, Categorisation, Lawful Basis
  • VIETNAMPDP-3 Data Subject Rights
  • ASD37-27 Outbound data loss prevention (Very Good)
  • DS-2 Ensure software supply chain security
  • CA-10 Selects and Develops Control Activities
  • CTDPA-1 Definitions
  • CAT-D3-2 Detective controls
  • 62351-14 Cyber security event logging

ISO 26000:2010 · 1 control

  • ISO-26000-6.7 Consumer issues

ISO/IEC 23894:2023 · 1 control

  • ISO23894-A.5 Privacy and Data Protection in AI
  • ISO-25012-4.11 Traceability

ISO/IEC 27043:2015 · 1 control

  • ISO27043-24 Logging and monitoring

ISO/SAE 21434 · 1 control

  • ISO21434-24 Logging and monitoring
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • RIDTPPA-11 Data Minimisation and Purpose Limitation
  • SAPAIA-4 Information Regulator Cooperation and Appeals
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • TEXASTDPSA-3 Sensitive Data, Children, Sale Notice
  • OB-CX.2 Granular Consent Management
  • UNICEFAI-4 Transparency, Explanation, Adult Capacity
  • CPSC-CS.3 Data Protection for Safety Systems
  • SO3.2 Regulatory frameworks for digital health

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 262 it maps to, and the evidence behind each claim, over MCP and REST.