TISAX Controls - Tips and Tricks

Updates to suggested controls needed to meet TISAX requirements.

Written By Micah

When using Strike Graph to manage your controls and adding on the TISAX framework, we recommend making a few updates to the control language to cover additional requirements. You can use the guidance below to make these changes to the controls within your Control Library and to activate additional controls that may be relevant to your organization.

Remember, you can and should edit the control descriptions to ensure that they accurately describe your processes.

Asset Inventory

Note that assets include secrets and patents. Refer to the TISAXv5 workbook for more details.

Business Continuity

In some organizations, the Business Continuity Plan will include a section on Disaster Recovery. Add the following to the existing control description: The organization has considered strategies for information and communication technology services as an element of its Business Continuity Plan.

Information Security Roles

Add the following to the existing control description: The responsibilities for ensuring that the information security management system conforms to ISO 27001 and reporting on the performance of the ISMS to top management, is available to the organization.

Legislative and Contractual Requirements

Remove the final sentence of the control description.

Non-Disclosure Agreement

Add the following to the control description: The NDA is regularly reviewed.

Operational Planning

This includes the first version of the Risk Assessment, Risk Treatment, and Risk Treatment Plan; the controls from Annex A stated as applicable in the Statement of Applicability; and the documents related to clauses 4 to 10.

Operating Procedure

Procedures should include:

  • configuration of systems

  • processing and handling of information

  • jobs scheduled

  • backups

  • recovery

  • monitoring of systems

  • handling errors and deviations

  • media handling

Risk Assessment Methodology

Ensure that privacy risks are considered. Strike Graph provides a recommended template.

Security Training

Include the following in the control description:

The training includes the Information Security Policy, how staff contribute to the effectiveness of the information security management system, the benefits of improved information security performance, and the implications of not conforming with the information security management system requirements.