VDA ISA IMPLEMENTATION FOR AUTOMATIVE
The VDA ISA standard for information security in the automotive industry provides auditable and uniform specifications for market participants. Following the introduction of an ISMS based on VDA ISA, a TISAX® audit or certification is performed by an ENX-accredited testing service provider.
Note: TISAX® is a registered trademark of the ENX Association. SEC4YOU has no business relationship with the ENX Association.
The advantages of VDA ISA and TISAX®
TISAX® is comparable to ISO 27001
The VDA ISA catalog is based on selected controls of ISO/IEC 27001, but specifies the required implementation in great detail in many measures. As a result, a TISAX® certificate can replace an ISO 27001 certification.
Uniform safety level in the automotive industry
Despite a large number of European testing service providers, the TISAX® label is awarded strictly according to uniform specifications. Market participants therefore rely on the uniform safety level of TISAX® certified companies.
TISAX® certification is required for new supply contracts with OEMs
If information is exchanged with OEMs and processed for them, these clients require a TISAX® label “Information Security High” or “Information Security Very High” from the automotive suppliers as a minimum. When handling prototypes, additionally “Protection of prototypes”. The purchasing departments of the large OEMs such as BMW, Audi, Volkswagen and others now also demand TISAX® from small companies.
Reduction of effort for audits by OEMs
The number of individual audits and supplier surveys is significantly and sustainably reduced by TISAX® certification. Certified suppliers are relieved by the elimination of these time-consuming individual audits. Once TISAX® labels have been issued, no further audits are required for a period of 3 years.
Recognition outside the automotive industry
A TISAX® certification according to Protection Level “Information Security High” or “Information Security Very High” is considered by experts to be of higher quality compared to ISO 27001 certification. Therefore, the TISAX® label speaks for the quality of a company’s information security.
The implementation of VDA ISA until the successful completion of the TISAX® assessment
We recommend carrying out the implementation in the following steps and provide support in all phases with consulting and project management:
Definition of the Protection Level
The requirement as to which protection level (high or very high) is necessary is usually the responsibility of your customer (OEM). It is important to clearly communicate which TISAX® label(s) is/are required and by what date.
GAP analysis
In an initial GAP analysis, an auditor or consultant compares the maturity level of information security against the requirements of the VDA ISA catalog. Before implementation, the target maturity level of 3.00 is usually not achieved.
Implementation VDA ISA and ISMS
The VDA ISA catalog is divided into the sections InfoSec Guidelines and Organization, Human Resources, Physical Security and Business Continuity, Identity and Access Management, IT Security and Cybersecurity, Supplier Security, and Compliance. A maturity level of 3 “Established” must be achieved in all sections. SEC4YOU can bring proven TISAX® compliant ISMS templates (including policies, ISMS manual, risk management, process descriptions, contingency plans) to this stage.
Pre-audit
In the course of a pre-audit, a TISAX® expert performs a GAP analysis and documents deviations from the target maturity level. These can be eliminated in this phase until the TISAX® audit.
TISAX® audit by the selected testing service provider
The audit by the testing service provider is carried out with the involvement of the specialist departments and detailed examination of evidence. In the first phase of the audit, the company must carry out a self-assessment and, if possible, provide documented evidence for the individual controls.
If the audit is successfully completed, the TISAX® label(s) is/are valid for 3 years.
Nice to know
YOUR ADVANTAGES
- Certified state-of-the-art information security
- Uniform security level in the automotive industry
- Reduced effort due to elimination of individual audits and supplier surveys
- TISAX® certification required for new supply contracts
QUICK LINKS
Questions about Security Awareness? Would you like to talk to an expert?