Current location - Education and Training Encyclopedia - Education and training - Tisax evaluation is divided into several levels.
Tisax evaluation is divided into several levels.
Three assessment levels (protection requirements) are distinguished: normal (1 level), high (level 2) and very high (level 3). The inspection method and work depend on the established safety requirements. TISAX is the European automotive industry standard information security assessment (ISA) directory, based on important aspects of information security, such as data protection and contact with third parties.

From the initial inspection to the final inspection, the whole TISAX testing process may take several months. If the test process cannot be successfully completed, you will not receive the TISAX label. If your company meets all the standards or only slightly deviates (so-called secondary deviation), the test report will be submitted to ENX. Once this is accepted, you will receive your (temporary) TISAX label. If there is a major deviation that must be corrected first, the label shall be applied from the date when the deviation is deemed to have been corrected.

What advantages does 1.TISAX certification provide?

The automotive industry standard information security assessment (TISAX) has been recognized by the supply chain participants in the global automotive industry, and it has established a unified information security level to enhance the confidence of the audited companies. Standardized TISAX assessment eliminates unnecessary repeated audits and saves your time and business expenses. Certification is valid for three years.

Second, the main process and steps of applying for TISAX:

1. Go to ENX official website to register and determine the level and location of information security scope for review. After the registration is completed, make an appointment with the audit company for the time and place of the audit and determine the fee.

2. First assessment. According to the detailed requirements of VDA ISA 4.04, find out the gap between the company's existing information security system and standards.

3. training. The company needs to carry out information security training for relevant personnel of the whole company and establish information security awareness.

4. Document preparation and information security operation. According to the standard requirements, write and implement relevant information security documents, and let the corresponding departments implement the documents. At the same time, missing software and hardware must be in place.

5. The company once again evaluates the current information security operation of the company according to VDA ISA. If the score can meet the requirements of TISAX, it can be adjusted to the best state to meet the external audit of TISAX auditors.

6. If the external audit is passed, wait for the report of the external audit institution; If it does not pass, re-examine it according to the situation until it passes. It should be noted that you must pass all the audits within 9 months, otherwise you need to start all over again.