TISAX® Technical Guide

Total Page:16

File Type:pdf, Size:1020Kb

TISAX® Technical Guide Technical Guide TISAX® - Trusted Information Security Assessment Exchange In today’s digitized business environment, information security has become an increasingly critical prerequisite for manufac- turers, supplies and service providers cooperating across the automotive value chain. The Trusted Information Security Assess- ment Exchange (TISAX®) provides members a standardized information security status to be shared among partners working throughout the automotive industry. Contents 1. TISAX® overview and benefits 6. ISO 27001 vs. TISAX® 2. Roles of participation 7. Defined TISAX® protection and assessment levels 3. TISAX® scopes of assessment 8. Test marks and labels 4. Established VDA ISA requirements 9. Assessment objectives for TISAX® prototype protection 5. Registered TISAX® subscriber Page 1 / 8 1. TISAX® overview and benefits Goals ct ra nt ENX Association TISAX® has been developed specifically for the automotive o R C e / g industry and aims to ensure the recognized integrity of your r is e tr id a v ti information security system. The TISAX® platform provides o o r n p t members standardized assessment of their information se- i d u A Interaction curity status to be shared with partners working throughout the value chain. Your achieved protection class is conven- during the iently registered on a dedicated digital platform and provid- assessment ed to selected members requesting your TISAX® status. process Partners in the TISAX® assessment include: • The ENX association Audit • An authorized audit provider Provider Participant • A participant company applying for certification Assessment TISAX® certification is valid for a period of three years. Registered partners share confidential information and need At its core, TISAX® aims to establish standardized labeling to be absolutely sure that others are continuously handling based on criteria common within the automotive industry. information according to established TISAX® standards. TISAX® has been developed to provide a community envi- Based on assessment results, the information security status ronment in which the performance and security of IT and IS of each registered participants is available on the online systems can be shared. platform. No TISAX® member has automatic access to the assessment results and the status of others. Selected partners Phases of TISAX® certification with which information is shared are determined by each 1. Registration on the TISAX® platform TISAX® participant on a case-by-case basis. 2. Selection of an audit provider 3. Preliminary verification of label/scope assessment, infor- TISAX®, VDA and ENX mation protection class, and simplified group assess- Established in early 2017, the TISAX® testing and exchange ment (if possible) mechanism was founded on the German Association of the 4. Execution and signing of the contract Automotive Industry (VDA) catalog of ISA (Information 5. Self-assessment (Assessment Level 1) Security Assessment) requirements. 6. Off-site audit (review of Assessment Level 1 according to documentation and label/scope confirmation or Founded in 2000, the ENX Association is a legally-inde- Assessment Level 2) optional pendent union of companies and national associations 7. On-site audit (Assessment Level 3) including Audi, BMW, Bosch, Continental, Daimler, DGA, 8. Label validation Ford, Magna, PSA Peugeot Citroën, Renault, Volkswagen 9. Audit information shared with exclusive TISAX® part- ANFAC (Spain), GALIA (France), SMMT (UK) and VDA ners designated by the audited member company (Germany) which supervises the performance of certified service providers, operates central ENX network services and supports providers with efficient solutions. Page 2 / 8 TISAX Assessment Flow Chart Registration KOM OM AL2 Choice of AP Self-assessment Temporary label AL3 9 months Label (validity: 3 years) Initial Non-conformities Follow-up assessment AL corrective action plan assessment KOM = Kick-off-meeting OM = Opening meeting AL = Assessment level AP = Audit Provider Benefits of TISAX® certification Active participant (e.g. supplier): Either orders assessment In addition to the added value of your recognized informa- or is called on by an OEM or customer to undergo assess- tion security status, TISAX® certification provides you the ment. The active participant then provides selected partners following advantages: access to the assessment results. • Increased credibility with a certified information security The three steps of participation: system 1. Registration • Cross-company recognition among TISAX® members Your selected TISAX® provider gathers information about • Strong strategies for effective risk management your company and determines the scope of your assessment. • Transparency through harmonized VDA ISA catalog 2. Assessment • Sharper focus on customer needs and expectations Assessment(s) is conducted by an accredited TISAX® audit • Internationally recognized listing on the TISAX® online provider. platform 3. Exchange • Complete control over who can access your assessment Assessment results and certification(s) are exclusively shared results with designated partners. • TISAX® assessment every three years eliminating time and money spent on multiple checks STEP 1 Clients can register on the TISAX® platform and are required 2. Roles of participation to follow a specific process to obtain a “participant number”. During the online TISAX® registration process candidates Member organizations participating in the exchange model must: may adapt either a passive or an active role according to each • Provide contact details and billing information particular circumstance: • Accept TISAX® terms and conditions Passive participant (e.g. OEM, automotive manufacturer): • Define the scope of the information security assessment Calls for another company such as a supplier to undergo assessment and requests access to the assessment results. Page 3 / 8 Roles of participation 1 Requests assessment from Gets 2 TISAX®-assessed Passive Participant Active Participant Shares result with 3 The audit scope is based on VDA ISA catalog. Audit dura- only you are authorized to decide the level at which your tion is calculated according to the determined scope and partner will have access. cannot be pre-calculated based solely on the structure of the TISAX® and ENX publication of the results and assessment organization. label on the TISAX® digital platform make your certification official. STEP 2 ® Assessment is broken into four sub-steps: 3. TISAX scopes of assessment • Assessment preparation The extent of preparation depends on the current maturity Scopes of assessment available to you: level of information security management system and must • Standard Scope be based on VDA ISA catalog requirements. Applied in the majority of cases, the standard scope is • Audit provider selection pre-defined to include all resources and processes used in Participants choose their preferred partner from the list of collecting, storing, and managing digital information. accredited TISAX® audit providers. • Customized Extended Scope • Information security assessment(s) Tailored to meet your needs beyond standard scope perim- The audit provider conducts assessment based on a scope eters. determined by the requirements of the requesting partner. • Customized Narrowed Scope Each assessment process consists of at least an initial audit, Tailored to meet only specific needs in a reduction of the with additional actions necessary for those who do not standard scope (no label can be issued). immediately pass. • Assessment result sharing Extended Scope Upon the completion of a successful audit, the report and results are shared at the approval of the active participant. dard S Stan cope STEP 3 Results are entered on the TISAX® platform to be exclusively shared with designated partners on a case-by-case basis. The ed arrow Scop content of your TISAX® report is structured in levels and N e Page 4 / 8 VDA ISA Protection TISAX® Assessment criteria catalog Level (PL) Assessment objective Level Information security high Information with high protection level AL 2 very high Information with very high protection level AL 3 Prototype Handling of prototypes with high protection level (for further AL 3 protection information please see chapter 10) Data protection according to German §11 BDSG Data protection high AL 2 (“Auftragsdatenverarbeitung”) Data protection with special categories of personal data, data protection according to German §11 BDSG very high AL 3 (“Auftragsdatenverarbeitung”), special categories according to German §3 section (9) BDSG (“Besondere Arten”) ® TISAX® certification culminates with an achieved assess- 5. Registered TISAX subscriber ment label symbolizing the assessment result. There are four different label categories that can be required by various Access to TISAX® is available to registered subscribers via partners. Defined at the beginning of the process, assess- the online TISAX® portal. Registration is the prerequisite ment objectives are audited and assigned the appropriate to choosing an accredited TISAX® auditor from the list of assessment level status upon successful completion of the authorized service providers. A single organization may reg- audit. Degrees of „ high“ or „very high“ define the achieved ister several locations and have a group assessment carried protection level in each category. out if needed. After assessment based on VDA ISA require- ments, active participants can provide information to be TISAX® assessment scope and duration
Recommended publications
  • PLM Industry Summary Editor: Christine Bennett Vol
    PLM Industry Summary Editor: Christine Bennett Vol. 10 No. 31 Friday 1 August 2008 Contents Acquisitions _______________________________________________________________________ 3 EDS Stockholders Approve Merger With Hewlett-Packard Company ______________________________3 Engineous Software Now a Part of SIMULIA _________________________________________________3 HP Announces European Commission Approval of EDS Acquisition; Agrees to Settle Litigation Relating to Acquisition ____________________________________________________________________________4 CIMdata News _____________________________________________________________________ 5 CIMdata Hosts PLM-Focused Event at the AMB International Exhibition for Metal Working: Special Attention on the relationship between PLM & Automation and PLM & Mechatronics _________________5 Cost Savings and Cycle Time Reductions are Still the Leading Drivers for PLM Implementations According to CIMdata’s Latest Poll __________________________________________________________________6 New Opinion Poll Posted on Establishing Formal Metrics to Track Improvement Resulting From the Use of Your PLM Solution _____________________________________________________________________7 Company News _____________________________________________________________________ 7 ANSYS Named to S&P Global Challengers List _______________________________________________7 Communications Service Provider Product Management is Broken ________________________________8 Complex Data Networks in Development Departments Need Standards - ENX
    [Show full text]
  • Application for ENX Network Registration
    Application for ENX Network Registration PRINT AND SEND YOUR SIGNED HARD COPY ENX Association Registration Application Bockenheimer Landstrasse 97-99 or scan and email to [email protected] 60325 Frankfurt am Main Germany Invoice Address Company Name Street Zip Code PO Box (optional) PO Box Zip Code (optional) City Country VAT Number Port Location (if different) First Communication Partner (FCP) Company Name Street Zip Code PO Box (optional) PO Box Zip Code (optional) City Country Contact (Your Company) Contact (FCP) Salutation First Name Family Name Title (Optional) Function (Optional) Department Phone Fax Email Address ENX Association • Application for ENX Registration Page 1/2 Application for ENX Registration Application Details Use Port Location as Postal Address for Contact (yes/no) Existing Company Registration Number (leave blank if none) Application Comment I agree with the data collection and data processing according to Part C – Data Privacy of the General Terms and Conditions of the ENX Registration and Utilisation. I also agree that ENX is entitled to make my personal data and information available to Certified Service Providers through an access restricted database frontend for communication purposes, including the provision of (service) information of such Certified Service Providers that may also be sent via email and/or phone to the contact information above. I accept the General Terms and Conditions of the ENX registration and utilisation (including the data privacy declaration above). Location and Date Stamp and Signature Further Questions? Contact Mr. Florian Gleich, Phone +49 69 9866927-60, [email protected] ENX Association • Application for ENX Registration Page 2/2 General Terms and Conditions of the ENX Registration and Utilisation Part A – Definitions and Registration users requires the establishment of an individual connection.
    [Show full text]
  • ENX Service Provider Datasheet
    ENX Service Provider Datasheet KPN International: Your gateway to the ENX ENX is a leading standard for secure and reliable communication in the automotive industry. Developed and governed by ENX Association, its use has been growing constantly since inception in 2000. Today it supports hundreds of applications in Automotive Competence critical areas like engineering, finance, logistics and supply chain management. ENX As an ENX Certified Service Provider, KPN accesses are offered worldwide by leading telecommunication providers, certified International boosts automotive productivity, by ENX Association. This data sheet is designed to give you a quick overview on one by delivering end-to-end connectivity of them, KPN International. in 180 countries and managing full ENX connectivity both on the KPN International MPLS network and via the KPN International ENX over Internet solution. Securely transfer engineering data and cut administration costs by replacing all your proprietary communication services with an ENX communication solution from KPN International. KPN International is a fully integrated business unit of To protect your data, all IPSec routers used by you and “KPN International has long-term, extensive KPN – the number one Dutch ICT provider and one of your partners will be authenticated via ENX digital experience with ENX. This enables us to ensure Europe’s leading telecommunication service providers. certificates issued by the ENX-selected Certification short lead times and fast service implementation. The KPN International portfolio delivers a comprehen- Authority (ENX CA). As an extra level of protection, One of our goals is to turn innovation into sive range of high-class data, communication and IP KPN International operates a separate ENX VPN within customer benefits in order to satisfy your needs.” services.
    [Show full text]
  • Smart Services World – Internet-Based Business Services Imprint
    Smart Services World – Internet-based Business Services Imprint Published by Federal Ministry for Economic Affairs and Energy Public Relations Division Scharnhorststr. 34–37 10115 Berlin The Federal Ministry for Economic Affairs and Energy was awarded the audit berufundfamilie® Text and editing for its family-friendly staff policy. The certificate LoeschHundLiepold is granted by berufundfamilie gGmbH, an initi- ative of the Hertie Foundation. Kommunikation GmbH, Berlin Design and production PRpetuum GmbH, Munich Last updated January 2017 Print MKL Druck GmbH & Co. KG, Ostbevern This brochure is published as part of the public relations work of the Feder- al Ministry for Economic Affairs and Energy. It is distributed free of charge and is not intended for sale. The distri- bution of this brochure at campaign events or at information stands run by political parties is prohibited, and po- litical party-related information or ad- vertising shall not be inserted in, print- ed on, or affixed to this publication. Content Smart Services World – Internet-based Business Services ..................................................................................................................................................................................................2 Projects ................................................................................................................................................................................................................................................4 AcRoSS ..............................................................................................................................................................................................................................................
    [Show full text]
  • Zero Distance
    Complex ICT solutions for Automotive Alexey Toskin, CEO, T-Systems CIS T-SYSTEMS – DEUTSCHE TELEKOM’S SUBSIDIARY FOR MAJOR CORPORATIONS. A GLOBAL PLAYER WITH GLOBAL RESOURCES. International Market position: presence: # 1 Automotive & Manufacturing in Germany Offices in 27 The biggest SAP hosting provider worldwide countries, global # 1 ICT provider in Germany delivery capability # 2 Systems Integration in Germany Among TOP #5 Big Data / Analytics in Germany Focus: Revenue: Large corporations, Approx. €8,2 billion (2015 figures) multi-national companies, automotive, public- Employees: sector and healthcare Approx. 46.000 (2015 figures) organizations Including 5.000 experts in automotive In Russia: Saint-Petersburg Moscow 1 100 employees Voronezh Global Automotive Presentation Set 17.08.2016 3 AUTO & IT CHALLENGES SOME KEY INDUSTRY CHALLENGES industry 4.0 + IOT Connected car big data Growing CLOUD ADOPTION 4 out of 10 German AcquiringBy 2035, actionableholistic, data Over 70% of industrial enterprises willintermodel become increasingly mobility manufacturing still use Industrie 4.0 criticalsolutions for the will design make and out companies are using appliances. operationup to 50% of systems, of the cloud applications By 2018, from 60 to 90 drivetrainsindustry ,sales safety. somewhere in their % of new cars will have features, and more. supply chain, with an embedded telematics another 25% considering solution/ it. Time-to-market gains in importance digital sales channel impact of customer loyalty 28% feel lateness to Since about half of sales By 2016, only 20% of market as one of the top leads of automotive Manufacturers will have reasons for innovation purchases will come from an integrated approach failure. digital sources, 70 to delivering service that percent of the marketing allows them to directly budget measure its impact on is expected to go towards customer loyalty and digital efforts.
    [Show full text]
  • Annual Report 2018 the Automotive Industry in Facts and Figures Annual Report 2018 the Automotive Industry in Facts and Figures Thank You
    Annual Report 2018 The automotive industry in facts and figures Annual Report 2018 The automotive industry in facts and figures Thank You. Mobility connects us. Lets us discover new things, meet our friends, get to work and run er- rands. It provides all of us with growth and prosperity. Today’s mobility is unthinkable were it not for the invention of the motorcar over 130 years ago. And mobility is constantly being reinvented. Resulting in increasingly safe, environmentally and climate-friendly mobility for the future. This is due to the 820,000 people who have made Germany the world’s leading automotive nation. Some of whom we present here. And to all of whom we say: Thank you. www.vda.de/en www.mobilitaet-von-morgen.de 6 FOREWORD FOREWORD 7 Foreword our industry. German car manufacturers our changeover premiums. In addition, and confidence. That’s what I stand for produced 16.5 million cars worldwide in our member companies support cities personally. And we are by no means resting 2017 – a new record high. They pro- and municipalities in numerous projects on our previous achievements. Manufac- duced 10.8 million cars at their locations and work on specific solutions. turers and suppliers are working together abroad, so that the foreign production intensively on continuing to strengthen also achieved a new record. At the same It is just as necessary to objectify the de- the international leading position of the time, domestic production remains at a bate. The fact is, nitrogen oxide emissions German automotive industry. This annual very high level at just under 5.7 million.
    [Show full text]
  • Annual Report 2018 Projects of the Associationinhalt
    Annual Report prostep ivip Association 2018 prostep ivip Association Phone +49 6151 9287-336 Dolivostraße 11 Fax +49 6151 9287-326 64293 Darmstadt [email protected] Germany www.prostep.org 2 prostep ivip Annual report 2018 Projects of the associationInhalt Content Editorial 5 List of Members 6 Highlights of the technical program 8 Public Relations Highlights 2018 10 Webinars 12 Projects of the Association 13 3D Measurement Data Management Implementor Forum (3D MDM IF) ................................................. 14 3D Measurement Data Management Workflow Forum (3D MDM WF) .................................................... 15 Additive Manufacturing Interfaces (AMI) ...................................................................................................... 16 CAx Implementor Forum (CAx IF) .................................................................................................................. 17 Cross-Discipline Lifecycle Collaboration Forum (CDLC Forum) ................................................................. 18 Code of PLM Openness (CPO) ....................................................................................................................... 19 Data Preparation for Data Analytics (DPDA) ................................................................................................. 20 ECAD Implementor Forum (ECAD IF) ........................................................................................................... 21 ECAD/MCAD-Collaboration Implementor Forum (EDMD IF) ...................................................................
    [Show full text]
  • Pricelist – Application for Registration by the ENX Association Valid from 01 January 2014 (Replacing All Former Pricelists)
    Pricelist – Application for Registration by the ENX Association Valid from 01 January 2014 (replacing all former pricelists) 1. Charges for an Application for Registration processed by ENX Association . The Customer shall pay ENX Association the charges as defined below. ENX Association will invoice the charges during the application process. The payment of the applicable charges is a prerequisite for the acceptance of a registration . Invoices shall be due for payment 30 (thirty) calendar days after the date of the invoice. All charges listed below are subject to German value added tax (VAT) as far as applicable. 2. Non-Recurring Charge (one-off fee) Item Application for registration EUR 1a First ENX access of a company 440,00 3. Discounted Charges (one-off fees) Item Application for registration EUR 1b Second and any further access of a company (identical legal entity) 0,00 2a Members of the ENX Association: Any ENX access (identical legal entity) 0,00 2b Members of the ENX Association: Accesses of daughter companies 110,00 4. Conditions concerning Discounted Charges . Access as defined in this price list is any physical access to the ENX network. Each access requires its own, individual registration number, even if an already registered user is aiming to establish further accesses. The 16 members of the Association are (as of 01 January 2014): Audi, BMW, Bosch, Continental, Daimler, DGA, Ford, Magna, PSA Peugeot Citroën, Renault, Volkswagen as well as the automotive associations AN- FAC (Spain), GALIA (France), SMMT (UK), OSD (Turkey) and VDA (Germany). The applicant must indicate during the application process that a certain discount is applicable.
    [Show full text]
  • ENX Service Provider Datasheet
    ENX Service Provider Datasheet The smart and efficient way to get your ENX connection ENX is a leading standard for secure and reliable communication in the automotive industry. Developed and governed by ENX Association, its use has been growing con- stantly since inception in 2000. Today it supports hundreds of applications in cirtical Automotive Competence areas like engineering, finance, logistics and supply chain management. ENX accesses A reliable IT infrastructure nowadays needs to be are offered worldwide by leading telecommmunication providers, certified by ENX one thing in particular: be available at all times. Association. This data sheet is designed to give you a quick overview on one of them, Without this prerequisite, even the best technolo- EWE TEL (formerly Business Communication Company with its brand "icyteas"). gies and the most optimised processes will be of no use. Our first class team with proven expertise realises an extensive and excellent managed services portfolio – to enable our customers to be even more flexible and dynamic. “The focus of SSC’s activity lies primarily on the collaboration between OEMs and their develop- ment partners and suppliers. SSC offers consulting, products and provision of services for a successful cooperation. We are experts in data exchange on any integration level and we are operating data exchange systems and supplier portals worldwide for Daimler AG and many other customers in diffe- The optimum alignement of business processes and fast. With our site near Germany’s biggest automotive rent industries. We are able to provide and support IT requires highly dynamic IT landscapes. For EWE TEL, centers, we have not only externally focused on the secure and reliable data exchange with our own this involves maximum speed and flexibility as well as automotive segment but also offer unparalleled and data exchange tool SWAN.
    [Show full text]
  • S660 - Thingworx Connectors- Unleash the Power Within Plm
    S660 - THINGWORX CONNECTORS- UNLEASH THE POWER WITHIN PLM Paul W. Downing President & CEO – PROSTEP INC liveworx.com #LIVEWORX SESSION OVERVIEW Accessing reliable and up-to-date PDM, SDM, ERP or ALM information at any time is essential. However, that can be challenging because the information is distributed across different systems to comply with regulatory restrictions, access restricted, or is represented in different formats. Companies in all industries are forced to work with heterogeneous IT system infrastructures. This presentation outlines how ThingWorx Connectors easily federate a vast selection of PDM, SDM, ERP and ALM systems of different vendors to the PTC ThingWorx and PTC Navigate toolset. Learn to leverage a framework to connect systems of any kind and build new applications leveraging data from any system. 1. Understand a solution for integrating any PLM system with ThingWorx and PTC Navigate. 2. Identify common risks and challenges of integrating multiple vendor systems. 3. Learn where to start with the requirements and scope of a multi-system integration project. #LIVEWORX 2 AGENDA Company Overview Technology Framework Thingworx Demos Integration Planning #LIVEWORX 3 AGENDA Company Overview Technology Framework Thingworx Demos Integration Planning #LIVEWORX 4 WHO IS PROSTEP ? A vendor neutral / independent engineering services and software company since 1993 Reseller Over 25 years experience with engineering interoperability, migration, intelligent documents, benchmarking, more Approximately 250 employees and consultants
    [Show full text]
  • Annual Report 2020
    Annual Report 2020 The automotive industry in facts and figures Annual Report 2020 – TheAnnual automotive Report industry 2020 facts in figures and Annual Report 2020. The automotive industry in facts and figures. 2 Foreword Foreword 3 Foreword commercial vehicle markets in particular. throughout Europe! This also requires need to forge further alliances in order to Ladies and gentlemen, dear readers, In view of this very difficult situation, we political action. Wrongly implemented, the develop forward­looking solutions. expect the German government to sup­ course of the EU Commission, especially The coronavirus pandemic poses challen­ ated with the car: artificial intelligence port a European fleet renewal program against the background of the coronavirus Shaping future­proof mobility that is ges to all areas of life that we have not opens the door to automated driving – for heavy­duty commercial vehicles or to crisis, can further aggravate the already climate­friendly, environmentally and experienced since the Federal Republic safer and more efficiently than ever tackle this project at national level. discernible economic and social burdens economically sustainable, socially minded of Germany came into existence. The before. Digital platforms allow us to and endanger jobs as well as the competi­ and customized is a historic task. But the economic consequences for the people combine the most diverse mobility The German government’s economic stim­ tiveness of companies and thus Europe. German automotive industry has every­ in our country are also often far­reaching solutions – tailored to every situation. ulus package to deal with the economic thing it takes to achieve this! An industrial and for many without precedent.
    [Show full text]
  • 2021 Sustainability Report
    2021 SUSTAINABILITY REPORT 1 GRI 102-50, 102-52, 102-54 Our 2021 Sustainability Report summarizes activities, achievements and progress for the calendar years 2019 and 2020. It aligns with the 10 principles of the United Nations Global Compact, the United Nations Sustainable Development Goals and has been prepared in accordance with the GRI Standards: Core option. Section 1 Leadership Perspective Section 7 Sustainable Procurement Section 2 Our Company Section 8 Service Performance Section 3 Our Approach Section 9 Charity & Community Support Section 4 Governance, Ethics & Compliance Section 10 Sustainability Reporting Section 5 Workplace Practices • Sustainability Performance Section 6 Environment • Materiality Matrix • GRI Content Index • Auditor Verification Statement For more information on our sustainability initiatives, visit our website www.bcdtravel.com/sustainability. SECTION 1 This report covers two years, 2019 and 2020, which in many ways represent polar opposites for LEADERSHIP BCD Travel, for our industry—and for the world. In this statement, we’ve chosen to speak particularly to 2020, a year that forced countries, companies PERSPECTIVE and individuals to change policies, priorities and behaviors. 1 GRI 102-14, 102-15 BUSINESS RESILIENCE DRIVEN BY PURPOSE For 45 years, BCD has been in the business of Align under our core strategies. Together, bringing people together through travel and we strengthened the partnership, simplicity and meetings, two activities made nearly impossible innovation that our people and our clients perceive since March 2020. But the same conditions and receive at BCD. We delivered experiences and that rocked our industry also highlighted our solutions that kept people safe, healthy, productive responsibility to our people, our clients and our and confident.
    [Show full text]