关于本检查清单

TISAX® certificate issued.TISAX®(Trusted Information Security Assessment Exchange,可信信息安全评估交换)是汽车行业广泛应用的信息安全评估机制,其依据为 VDA 信息安全评估(ISA)目录。TISAX® 采用评估模式,而非认证模式。请注意,TISAX® 不颁发证书。

本检查清单帮助您在安排 TISAX® 评估前,根据 VDA ISA 评估领域对组织当前的信息安全管理状况进行自查。请逐项审查各评估领域,并根据组织目前的实际实施情况,将每项内容标记为“符合”“部分符合”或“不符合”。

关于评估等级的说明

TISAX® 评估分为不同的评估等级(AL1–AL3)。适用的评估等级及测试深度取决于所涉及的信息类型,以及您与业务合作伙伴共同确定的评估范围。对于较高等级的评估,通常需要由审核员开展现场或远程验证,而不仅仅依靠企业自我评估完成。

如何使用本检查清单

  • 为每个评估领域指定负责人(例如信息安全负责人、人力资源部门、设施管理部门等)
  • 请根据组织实际情况如实填写每项内容。“部分符合”同样是一种有效且具有参考价值的评估结果
  • 使用最后一页的评分指南,识别需要优先改进的评估领域
  • 随着评估范围或业务合作伙伴要求的变化,定期重新审查和更新本检查清单
TISAX® Readiness Checklist

TISAX® Readiness Checklist

Check your organisation's current state against the VDA ISA domains before scheduling a TISAX® assessment.

32 items · 8 domains · Yes / Partial / No
Your progress 0 of 32 answered
1

Information Security Policy & Organisation

A documented information security policy exists and is approved by management.

Information security responsibilities are formally assigned within the organisation.

The policy is reviewed and updated on a defined cycle.

Information security objectives are linked to business risk, not treated as a standalone IT topic.

2

Human Resources Security & Awareness

Confidentiality obligations are included in employment contracts or equivalent agreements.

New employees receive information security awareness training during onboarding.

Regular refresher training is provided to all staff with access to sensitive information.

A defined process exists for revoking access when employees leave or change roles.

3

Asset Management

An inventory of information assets (data, systems, devices) is maintained and kept current.

Assets are classified according to sensitivity (e.g. public, internal, confidential, strictly confidential).

Rules for handling and labelling classified information are documented and followed.

Removable media and mobile devices are covered by defined handling rules.

4

Physical & Environmental Security

Access to buildings and sensitive areas is controlled (badges, visitor logs, escort rules).

Server rooms and data centres have restricted access separate from general office access.

Clear desk and clear screen practices are defined and observed.

Environmental risks (fire, water, power loss) are addressed for critical infrastructure.

5

IT Security: Access Control & Cryptography

User access follows a least-privilege, need-to-know principle.

Access rights are reviewed on a defined schedule and removed promptly when no longer needed.

Multi-factor authentication is used for remote access and privileged accounts.

Encryption is applied to sensitive data at rest and in transit, aligned with a defined standard.

Patch management and vulnerability handling follow a documented process.

6

Supplier & Third-Party Relationships

Information security requirements are included in supplier and subcontractor agreements.

Third parties with access to sensitive information are assessed before onboarding.

A process exists to monitor supplier compliance with agreed security requirements on an ongoing basis.

7

Incident Management & Business Continuity

A documented process exists for reporting and handling information security incidents.

Roles and escalation paths for incident response are defined and known to relevant staff.

Business continuity and disaster recovery plans exist for critical systems and processes.

Continuity plans are tested or exercised on a defined cycle.

8

Data Protection (Privacy)

A data protection framework aligned with applicable privacy law (e.g. GDPR) is in place.

Processing of personal data is documented, including legal basis and retention periods.

A process exists for handling data subject requests and personal data breaches.

Safeguards are in place for international transfers of personal data (e.g. standard contractual clauses).

Your Readiness Score

0 of 64 points

Results by domain

下一步行动

完成自查是迈向 TISAX® 评估的重要起点,而不是最终目标。DQS 根据您的业务合作伙伴所要求的评估等级和范围,提供独立的 TISAX® 评估服务。欢迎联系 DQS,与我们共同确定适合您组织的评估等级和评估模块,并安排后续评估时间。

联系我们