Wednesday, September 23, 2026

TISAX® – From TISAX Awareness to Workplace Implementation & Assessment Readiness

In today’s connected automotive industry, protecting information is as critical as protecting the product itself. This two-day program introduces participants to the TISAX® framework, VDA ISA requirements, assessment process and information-security practices relevant to automotive manufacturing.


Through real-world automotive scenarios, hands-on exercises, mock assessments, case studies and workplace activities, participants will learn how to identify sensitive information, assess risks, strengthen controls, respond to incidents and prepare meaningful evidence for assessment.

The program moves beyond awareness to focus on one practical question:

“What can I do in my workplace today to protect information, strengthen trust and support TISAX readiness?”

The course follows the TISAX journey of Registration → Assessment → Exchange, as structured in the ENX TISAX Participant Handbook.


Training theme

“Protect the Information. Protect the Process. Protect the Product. Protect the Customer.”


1. The Design of the 2-Day Program

70:30 model: 30% Concepts + 70% Activities / Case Studies / Simulations / Workplace Application

The entire two days can revolve around one continuous fictional automobile-manufacturing company:

“Ansari Auto Systems Pvt. Ltd.”

Participants become the company's:

  • Engineering team
  • Production team
  • IT team
  • OT/Automation team
  • Quality team
  • Purchase team
  • HR team
  • Security team
  • Management team

Their mission:

“An OEM customer has asked ANSARI Auto Systems to demonstrate a defined level of information-security management through TISAX.”

The three major TISAX steps as Registration → Assessment → Exchange.


DAY 1

UNDERSTAND – IDENTIFY – CLASSIFY – PROTECT

9:00–9:30

SESSION 1 – Opening: Why Does TISAX Matter?

Learning objectives

Participants understand:

  • Why automotive companies require information-security assurance
  • What TISAX is
  • Why OEMs ask suppliers to demonstrate information security
  • Why information security is not just an IT responsibility
  • Relationship between information security and manufacturing continuity

The handbook explains that TISAX enables companies to prove that their information-security management complies with a defined level according to the Information Security Assessment requirements and facilitates sharing the assessment result with partners.


Opening Activity

“WHAT WOULD A COMPETITOR WANT?”

Give every table 5 minutes.

Ask:

If a competitor wanted to reproduce our next-generation vehicle, what information would they want?

Participants list:

  • CAD
  • BOM
  • Product specifications
  • Supplier details
  • Production parameters
  • Test results
  • Prototype photographs
  • Software
  • ECU information
  • Manufacturing process
  • Quality parameters
  • Cost information
  • Customer data
  • Future model plans

Then ask:

“Where does each piece of information exist?”

This creates the connection:

Information → Person → Process → System → Supplier → Risk


9:30–10:15

SESSION 2 – TISAX FUNDAMENTALS

Content

Explain:

TISAX

Trusted Information Security Assessment Exchange

VDA ISA (stands for Verband der Automobilindustrie Information Security Assessment (in German: Verband der Automobilindustrie - Informationssicherheits-Assessment). In English, it translates to the German Association of the Automotive Industry Information Security Assessment)

Information Security Assessment

Assessment Objectives

Assessment

TISAX Labels

Exchange of Assessment Results

The handbook specifically identifies the ISA as the basis for defined information-security requirements and explains that the handbook is intended to help participants navigate the TISAX process.


Activity (Give participants cards) – “TISAX Jigsaw”



  • OEM requirement
  • Scope
  • Assessment objective
  • Protection need
  • ISA
  • Self-assessment
  • Audit provider
  • Initial assessment
  • Finding
  • Corrective action
  • Follow-up
  • TISAX label
  • Exchange

Teams must construct the process.


10:15–10:30

BREAK


10:30–11:30

SESSION 3 – THE TISAX JOURNEY

Registration → Assessment → Exchange

Stage 1 – Registration

Participants understand:

  • Participant
  • Scope
  • Locations
  • Contacts
  • Assessment objectives
  • Protection needs
  • Assessment levels

The handbook has extensive guidance on registration preparation, assessment scope, scope description, standard scope, scope tailoring, locations, contacts and publication/sharing.


Hands-On Exercise Give each group:

“CREATE YOUR TISAX SCOPE”

ANSARI Auto Systems

Locations:

  • Corporate office
  • R&D centre
  • Manufacturing plant
  • Warehouse
  • Testing facility

Participants determine:

What should be inside the assessment scope?

What should be outside?

Which locations process sensitive information?

Which locations need further investigation?


WORKSHEET 1

TISAX Scope Identification

Location

Activity

Information handled

Systems

Sensitive information?

Include in scope?

Reason

R&D

CAD

Product design

PLM

Yes

Plant

Production

Process data

MES

Yes

Warehouse

Logistics

Dispatch data

ERP

HR

Employee records

Personal data

HRMS


11:30–12:30

SESSION 4 – ASSESSMENT OBJECTIVES & PROTECTION NEEDS

This is an important area that should not be diluted into generic cybersecurity terminology.

The handbook identifies assessment objectives such as:

  • Confidential
  • Strictly confidential
  • High availability
  • Very high availability
  • Prototype parts
  • Prototype vehicles
  • Test vehicles
  • Protection of prototypes during events/photo shoots
  • Data
  • Special data

and explains that assessment objectives are a key input to the TISAX assessment process.


Activity – “WHICH OBJECTIVE?”

Give teams scenarios.

Scenario 1 - A new vehicle prototype is being tested.

Scenario 2 - Highly sensitive CAD data is exchanged with an OEM.

Scenario 3 - Production information must remain available to support manufacturing.

Scenario 4 - Prototype components are displayed at an event.

Scenario 5 - A supplier processes personal data on behalf of the organization.

Teams identify which assessment-objective concepts are relevant.

Important trainer note

Do not ask participants to decide their organization's actual TISAX assessment objectives during a general awareness session. Explain that actual selection is an organizational/TISAX scoping decision.


12:30–1:15

LUNCH


1:15–2:15

SESSION 5 – INFORMATION ASSETS & CLASSIFICATION

“If You Don't Know What You Have, You Cannot Protect It.”

Participants identify:

Physical information

  • Drawings
  • Printed reports
  • Prototype documents
  • Manuals
  • Visitor registers

Digital information

  • CAD
  • ERP
  • MES
  • QMS
  • PLM
  • Emails
  • Databases
  • Source code
  • Cloud systems

Manufacturing information

  • PLC configurations
  • Robot programs
  • Machine parameters
  • Process sheets
  • Production schedules
  • Quality parameters

HANDS-ON ACTIVITY

“INFORMATION ASSET HUNT”

Give each team 20 minutes to walk mentally through their own department.

They identify:

5 critical information assets

For each:

  • Owner
  • Location
  • User
  • Classification
  • Business impact
  • Security risk
  • Existing control

WORKSHEET 2 – ASSET REGISTER

Asset

Owner

Location

Who uses it?

Protection need

Existing control

Gap

CAD files

Engineering

PLM

Design team

Very high

Production schedule

Production

MES

Production

High

PLC programme

Automation

OT server

Maintenance

High

Supplier database

Purchase

ERP

Purchase

High


2:15–3:00

SESSION 6 – ISA: CONTROL QUESTIONS & REQUIREMENTS

The handbook explains that the ISA contains three criteria catalogues:

  1. Information Security
  2. Prototype Protection
  3. Data Protection

and that these contain control questions and associated requirements.


Activity – “THE TISAX QUESTION”

Give teams a control question scenario:

“How do you control access to confidential engineering information?”

Participants must answer:

1. What is our policy?

2. What is our process?

3. Who is responsible?

4. What system enforces it?

5. What evidence exists?

6. How do we know it works?


The Golden TISAX Evidence Model

Teach participants:

POLICY - What do we say?

PROCESS - What do we do?

IMPLEMENTATION - How is it actually performed?

EVIDENCE - What proves it?

EFFECTIVENESS - How do we know it works?


3:00–3:15

BREAK


3:15–4:00

SESSION 7 – SELF-ASSESSMENT & MATURITY

The handbook specifically addresses:

  • Criteria catalogues
  • Chapters
  • Control questions
  • Self-assessment fields
  • Objectives
  • Requirements
  • Maturity levels
  • Conducting the self-assessment
  • Interpreting the result.

Hands-On Exercise

“RED – AMBER – GREEN”

Participants take 10 simulated controls.

For each:

🟢 Implemented
🟡 Partially implemented
🔴 Not implemented

Then they must answer:

“What evidence do you have?”

This prevents the common mistake of confusing:

“We have a policy”

with

“The control is actually implemented and effective.”

Yes. I recommend running this as a 60–75 minute TISAX self-assessment simulation, rather than simply asking participants to choose red/amber/green.

One important distinction: Red–Amber–Green is a training simplification, not the TISAX/ISA maturity-scale itself. The TISAX Participant Handbook describes six maturity levels, from 0 – Incomplete through 5 – Optimizing, and participants assess the current state for each applicable control question. The exercise can therefore teach participants the thinking process behind the formal self-assessment without pretending that RAG is the official scoring method.

How to conduct the activity

Activity title

RED – AMBER – GREEN: “SHOW ME THE EVIDENCE!”

Recommended duration: 60–75 minutes

Team size

4–6 participants per team

Materials

Prepare:

  • 10 control cards per team
  • Red / Amber / Green cards
  • Evidence cards
  • A3 worksheet
  • Sticky notes
  • Marker pens
  • Timer
  • Optional laptop/projector

STEP 1 – Set the scenario

Tell participants:

“You are the TISAX readiness team of an automobile manufacturing plant. An OEM customer has requested evidence that your information-security management is appropriately implemented. You are conducting a preliminary self-assessment.”

Then give them the rule:

Do not answer based on what you believe should happen.

Answer based on:

“What is actually happening in our workplace, and what evidence can we produce?”

This is consistent with the handbook's approach that the self-assessment is based on the current state of the information-security management system, with participants determining the maturity level for each applicable question.


STEP 2 – Give each team the 10 simulated controls

These should be training scenarios, not presented as verbatim TISAX/ISA control wording.

CONTROL CARD 1 – ACCESS CONTROL

Situation

Only authorized employees should access confidential engineering and CAD information.

Ask the team:

Is this:

🟢 Implemented
🟡 Partially implemented
🔴 Not implemented?

Then ask:

“Show me the evidence.”

Possible evidence

  • Access-control policy
  • User-access list
  • Authorization records
  • Role matrix
  • Access review records
  • System screenshots
  • Approval records

Challenge question

“Can you show me evidence that the control is actually operating?”


CONTROL CARD 2 – JOINER / MOVER / LEAVER

Situation

When an employee joins, changes role or leaves, their system access is appropriately created, modified or removed.

Evidence could include:

  • HR notification
  • IT ticket
  • Access request
  • Approval record
  • Deactivation record
  • Exit checklist
  • Periodic access review

Killer question

“Can you prove that someone who left six months ago no longer has access?”

This usually creates excellent discussion.


CONTROL CARD 3 – INFORMATION CLASSIFICATION

Situation

Confidential engineering information is identified and handled according to its protection requirements.

Evidence

  • Information-classification policy
  • Classification labels
  • Document examples
  • Employee training
  • Data-handling procedure
  • System configuration

Challenge

Show participants two documents:

A: Public company brochure

B: New vehicle CAD drawing

Ask:

“Should they be handled in the same way?”


CONTROL CARD 4 – SUPPLIER ACCESS

Situation

External suppliers receive only the access required for their approved business activity.

Evidence

  • Supplier agreement
  • NDA
  • Access approval
  • VPN records
  • User list
  • Access review
  • Contractual security requirements
  • Termination records

Challenge

“Supplier X has completed its project. Who ensures its access is removed?”


CONTROL CARD 5 – VISITOR MANAGEMENT

Situation

Visitors and contractors entering restricted areas are identified, authorized and appropriately controlled.

Evidence

  • Visitor register
  • ID verification
  • Visitor badge
  • Escort records
  • NDA
  • Restricted-area procedure
  • CCTV/access-control records

Scenario

A supplier engineer says:
“I forgot my ID, but your production manager knows me.”

Ask:

“Do we let him in?”


CONTROL CARD 6 – USB / REMOVABLE MEDIA

Situation

Removable media is controlled to reduce unauthorized transfer of information or introduction of malicious software.

Evidence

  • USB policy
  • Endpoint configuration
  • Approved-device list
  • Exception approval
  • USB activity logs
  • Awareness records

Scenario

A maintenance engineer brings a personal USB containing a machine configuration file.

Ask:

“What should happen?”


CONTROL CARD 7 – INCIDENT REPORTING

Situation

Employees know how to report suspected information-security incidents and incidents are handled through a defined process.

Scenario

An employee accidentally sends a confidential drawing to the wrong email address.

Ask:

“What should the employee do in the first five minutes?”

Evidence

  • Incident-response procedure
  • Incident reporting form
  • Ticket
  • Incident register
  • Escalation matrix
  • Training records
  • Previous incident records

CONTROL CARD 8 – BACKUP & RECOVERY

Situation

Critical information is backed up and recovery capability is periodically verified.

Evidence

  • Backup policy
  • Backup schedule
  • Backup logs
  • Recovery test records
  • Restore evidence
  • Backup monitoring
  • Business continuity documentation

Killer question

“You say we have backups. Show me evidence that we have successfully restored from one.”

This teaches the difference between:

Backup exists

and

Recovery capability has been demonstrated.


CONTROL CARD 9 – PROTOTYPE PROTECTION

Situation

Prototype vehicles and components are protected from unauthorized access, photography and disclosure.

Scenario

A contractor takes a photograph inside the prototype area.

Ask:

“What controls should have prevented this?”

Evidence

  • Prototype protection procedure
  • Restricted-area access
  • Photography policy
  • Visitor controls
  • NDA
  • Security briefing
  • CCTV/access logs
  • Incident records

This connects particularly well with the TISAX prototype-protection assessment objectives described in the handbook.


CONTROL CARD 10 – SECURITY AWARENESS

Situation

Employees receive appropriate information-security awareness and the organization maintains evidence of that activity.

Evidence

  • Training calendar
  • Attendance
  • LMS records
  • Assessment results
  • Awareness campaigns
  • Phishing simulation results
  • Refresher training records

Killer question

“You conducted training last year. How do you know employees actually understood it?”


STEP 3 – The RAG Decision

Give teams three cards:

🟢 GREEN

IMPLEMENTED

The control appears to be implemented and the team can identify credible evidence.


🟡 AMBER

PARTIALLY IMPLEMENTED

Something exists, but there is a gap.

Examples:

  • Policy exists but employees don't consistently follow it.
  • Access review occurs but not for all systems.
  • Training occurs but evidence is incomplete.
  • Supplier controls exist for some suppliers but not others.

🔴 RED

NOT IMPLEMENTED / NOT DEMONSTRABLE

The control is absent, ineffective or the team cannot demonstrate that it is implemented.

Important trainer point

Don't automatically equate:

“We can't find the evidence”

with

“The control doesn't exist.”

Instead ask:

“Who owns the evidence, where should it exist, and can it be demonstrated?”

That distinction is important in a real assessment.


STEP 4 – THE MOST IMPORTANT QUESTION

After every RAG decision, the trainer asks:

“SHOW ME THE EVIDENCE.”

This should become the signature phrase of the exercise.

For example:

Participant:

“Green. We have access control.”

Trainer:

“Show me the evidence.”

Participant:

“We have an access-control policy.”

Trainer:

“That's evidence that a policy exists. Show me evidence that the control is implemented.”

Then:

“Show me evidence that it is working.”

This creates the learning breakthrough.


STEP 5 – Introduce the 5 Evidence Questions

For every control, ask:

1. WHAT?

What control exists?

2. WHO?

Who owns it?

3. HOW?

How is it implemented?

4. WHERE?

Where is the evidence?

5. HOW DO YOU KNOW?

How do you know it is effective?


STEP 6 – Add the “EVIDENCE CARD” GAME

This makes the activity much more interactive.

Prepare evidence cards such as:

Evidence cards

  • Policy document
  • Procedure
  • Training attendance
  • Access-control list
  • Approval email
  • System screenshot
  • Audit report
  • Log file
  • Incident record
  • Visitor register
  • CCTV record
  • Contract
  • NDA
  • Backup log
  • Recovery-test report
  • Risk assessment
  • KPI report
  • Management review
  • Corrective-action record

Mix them up.

Teams must select the most appropriate evidence for each control.


Example

Control:

Supplier access is controlled.

Team chooses:

Company brochure
Employee attendance sheet
General cybersecurity policy

But selects:

Supplier access approval
Supplier contract
VPN access record
User-access list
Periodic access review

Then ask:

“Which piece of evidence would be strongest?”

Now the participants are thinking like assessors.


STEP 7 – Introduce “POLICY vs PRACTICE vs EVIDENCE”

Put this on the screen:

LEVEL 1

POLICY

“We have a procedure.”

LEVEL 2

PRACTICE

“People actually follow the procedure.”

LEVEL 3

EVIDENCE

“We can demonstrate that it is being followed.”

LEVEL 4

EFFECTIVENESS

“We can demonstrate that it achieves its objective.”

This is an especially important discussion because the handbook explains that ISA requirements need to be interpreted in the context and spirit of the objective, and that the audit provider considers the organization's actual implementation.


STEP 8 – Give Them the Scoring Sheet

TISAX RAG SELF-ASSESSMENT WORKSHEET

#

Simulated Control

RAG

What evidence exists?

Evidence owner

Gap

Immediate action

1

Access control

🟢

2

Joiner/Mover/Leaver

🟡

3

Classification

🔴

4

Supplier access

5

Visitor management

6

USB control

7

Incident reporting

8

Backup/recovery

9

Prototype protection

10

Awareness


STEP 9 – The “AUDITOR ATTACK” ROUND

Now make the exercise more challenging.

Tell participants:

“The auditor is not satisfied with your first answer.”

For every Green answer, ask one of these:

Auditor Question 1

“Show me the document.”

Auditor Question 2

“Show me a recent record.”

Auditor Question 3

“Who owns this control?”

Auditor Question 4

“How frequently is it reviewed?”

Auditor Question 5

“Show me what happens when the control fails.”

Auditor Question 6

“How do you know employees follow it?”

Auditor Question 7

“What happened during the last review?”

Auditor Question 8

“Can you demonstrate effectiveness?”

This is where the exercise becomes powerful.


STEP 10 – Convert RED/AMBER into Corrective Actions

After all 10 controls have been assessed, tell teams:

“You have 20 minutes to turn your Amber and Red findings into an action plan.”

Use:

Finding

Root cause

Corrective action

Owner

Deadline

Evidence of closure

USB control weak

No formal process

Establish approved USB procedure

IT

15 days

Policy + configuration

Supplier access not reviewed

No periodic review

Quarterly access review

IT/Purchase

30 days

Review report

Visitor controls inconsistent

Process varies by gate

Standardize procedure

Security

15 days

Checklist + records


STEP 11 – Connect It to Actual TISAX Maturity

Now reveal the formal concept.

Tell participants:

“Our Red/Amber/Green exercise is only a learning tool. In the actual ISA self-assessment, maturity is evaluated using six maturity levels.”

ISA Level

Simplified interpretation

0

Incomplete

1

Performed

2

Managed

3

Established

4

Predictable

5

Optimizing

The handbook provides these informal descriptions and explains that maturity is rated per question in the self-assessment.

Then ask:

Green doesn't automatically mean “Level 5.”

This is an important learning point.

A control may be operating but still not be mature, systematically managed, monitored or continuously improved.


STEP 12 – Final Debrief

Ask every team:

Question 1 - Which control did you initially mark Green but later discover had weak evidence?

Question 2 - Which control became Amber after the auditor questions?

Question 3 - Which control became Red?

Question 4 - What evidence was hardest to produce?

Question 5 - Who actually owns the evidence?

Question 6 - What can you fix within 15 days?


THE BIG TAKEAWAY

Put this on the final slide:

DON'T SAY:

“We have a policy.”

SAY:

“Here is our requirement.”

“Here is our process.”

“Here is the evidence.”

“Here is the owner.”

“Here is how we monitor it.”

“Here is how we know it is effective.”

That is the mindset you want participants to carry back to the automobile plant.

The handbook itself emphasizes that the self-assessment evaluates the current state of the information-security management system and that the assessment ultimately checks whether applicable requirements conform.

Trainer's final challenge

End with:

“If an auditor walked into your department tomorrow morning and asked: ‘Show me the evidence’ — what would you be able to produce in five minutes?”

That question will make the activity memorable and immediately applicable.

 


4:00–4:45

SESSION 8 – AUTOMOTIVE CASE STUDY

CASE: “THE LEAKED CAD FILE”

Situation

A design engineer receives a WhatsApp message:

“The supplier's email isn't working. Please send the latest drawing here.”

The engineer sends it.

Three days later:

The supplier reports that the drawing has appeared outside the approved organization.



Teams investigate

What went wrong?

  • Unauthorized channel
  • Lack of verification
  • Information classification failure
  • Supplier-control weakness
  • Human-factor failure
  • Potential contractual issue

Teams develop:

Immediate action

Containment

Investigation

Reporting

Corrective action

Preventive action



4:45–5:15

SESSION 9 – MOVIE-BASED LEARNING

Use short clips only, followed by structured discussion.

Bollywood / Indian cinema options

Special 26

Theme:

Identity verification / impersonation / trust

Question:

“Does looking official make someone authorized?”



Raazi

Theme:

Need-to-know / information secrecy / communication discipline

Question:

“Who really needs to know sensitive information?”



A Wednesday!

Theme:

Crisis communication / information / decision-making

Question:

“What happens when information is incomplete and time is limited?”



2.0

Theme:

Connected technology / digital dependency

Question:

“What happens when connected systems become part of a wider attack surface?”



5:15–5:30

DAY 1 REFLECTION

Every participant completes:

“3–2–1”

3 things I learned







2 risks I identified in my work





1 action I will implement tomorrow



DAY 2

ASSESS – RESPOND – RECOVER – IMPROVE


9:00–9:45

SESSION 10 – TISAX ASSESSMENT PROCESS

The handbook identifies three TISAX assessment types:

  1. Initial assessment
  2. Corrective action plan assessment
  3. Follow-up assessment

The initial assessment always occurs; the other two may occur depending on findings and corrective actions.


ROLE PLAY

“YOU ARE BEING ASSESSED”

Roles:

  • Auditor
  • IT manager
  • Engineering manager
  • HR
  • Production manager
  • Security
  • Observer

Auditor asks:

“Show me how access to confidential engineering information is controlled.”

The manager must demonstrate:

Requirement → Process → Evidence → Effectiveness


9:45–10:30

SESSION 11 – FINDINGS & CONFORMITY

Teach the concept of conformity.

The handbook explains that the assessment checks applicable requirements individually and distinguishes different types of findings, with the overall assessment result potentially being conform, minor non-conform or major non-conform.


Activity – “AUDITOR FINDING”

Give participants examples.

Finding A - Policy exists but has not been reviewed.

Finding B - Access rights exist for an employee who left months ago.

Finding C - Critical security control is absent.

Teams identify:

  • What is the problem?
  • What is the root cause?
  • What evidence would the auditor need?
  • What corrective action is appropriate?

10:30–10:45

BREAK


10:45–11:45

SESSION 12 – CORRECTIVE ACTION PLAN

This should be one of the most practical sessions.

The handbook explains that corrective actions should address the root cause, critical risks should be appropriately mitigated, and implementation periods must be appropriate.


WORKSHEET 3

Corrective Action Plan

Finding

Root cause

Immediate containment

Corrective action

Owner

Deadline

Evidence

Effectiveness verification

Shared account

Poor access design

Disable account

Create individual accounts

IT

Supplier access

No review process

Suspend access

Quarterly review

IT/Supplier  

Uncontrolled USB

No procedure

Block device

Implement removable-media control

IT


11:45–12:30

SESSION 13 – FOLLOW-UP ASSESSMENT

Explain:

Initial Assessment

Findings

Corrective Action

Follow-up Assessment

Resolution

The handbook states that the purpose of the follow-up assessment is to determine whether previously identified non-conformities have been resolved.


Activity

“CLOSE THE FINDING”

Each team receives a finding.

They must produce:

  1. Root cause
  2. Corrective action
  3. Evidence
  4. Effectiveness measure
  5. Closure criteria

12:30–1:15

LUNCH


1:15–2:15

SESSION 14 – IT/OT & SHOPFLOOR SECURITY

“WHEN CYBERSECURITY STOPS THE FACTORY”

Map:

Corporate IT

Plant IT

MES

SCADA

PLC

Robot

Machine

Product


REALISTIC CASE STUDY

8:30 AM - Production line starts.

8:45 - MES becomes unavailable.

9:00 - Operator reports abnormal machine behaviour.

9:15 - Maintenance discovers an unauthorized USB.

9:30 - IT detects suspicious network traffic.

10:00 - Production management wants to continue.


TEAM TASK

Determine:

Who acts?

Who decides?

Who communicates?

What is isolated?

What evidence is preserved?

What production activity can safely continue?

What must stop?


WORKSHEET 4

IT/OT Dependency Map

Process

System

OT dependency

Criticality

Manual fallback

Owner

Production planning

ERP/MES

Welding

PLC

Inspection

QMS

Dispatch

ERP


2:15–3:00

SESSION 15 – SUPPLIER & THIRD-PARTY SECURITY

Participants map:

OEM

Tier 1

Tier 2

Tier 3

Logistics

Service providers


CASE STUDY

A supplier has:

  • Remote access
  • Engineering data
  • VPN
  • Contractor access
  • Shared accounts
  • No documented access review

Team task

Build a supplier-security action plan.


SUPPLIER CHECKLIST

NDA

Information classification

Security requirements

Access approval

MFA

Remote access control

User lifecycle

Incident notification

Data return/deletion

Backup/recovery

Periodic review

Contract termination controls


3:00–3:15

BREAK


3:15–4:00

SESSION 16 – TISAX INCIDENT RESPONSE WAR ROOM

Scenario: “THE 9:00 AM INCIDENT”

A ransomware-like incident has affected:

  • Engineering server
  • Production workstation
  • Shared drive
  • MES connectivity

A supplier calls saying:

“We have received a suspicious engineering file from your organization.”


Participants have 30 minutes.

They must produce:

1. Immediate containment

2. Incident notification

3. Evidence preservation

4. Business continuity

5. Supplier communication

6. Management communication

7. Recovery

8. Lessons learned


INCIDENT LOG

Time

Event

Action

Owner

Evidence

Decision

09:00

09:10

09:20

09:30


4:00–4:45

SESSION 17 – MOCK TISAX ASSESSMENT

This is the capstone exercise.

Create five audit stations:

Station 1 - Information Security

Station 2 - Prototype Protection

Station 3 - Data Protection

Station 4 - Physical / IT / OT Security

Station 5 - Supplier & Incident Management

The ISA handbook structure includes these three criteria catalogues: information security, prototype protection and data protection.


MOCK AUDIT QUESTION BANK

Information Security

How do you classify information?

How do you control access?

How do you remove access when an employee leaves?

How do you manage incidents?

How do you manage suppliers?

Prototype Protection

Who can access prototype areas?

Can employees photograph prototypes?

How are visitors controlled?

How are prototype documents protected?

Data Protection

Who processes personal data?

Why do they have access?

How is access controlled?

How is information retained/deleted?


4:45–5:15

SESSION 18 – THE TISAX IMPLEMENTATION ROADMAP

TODAY

Identify 5 critical information assets

Identify their owners

Review your own access

Stop unauthorized information-sharing channels

Report security weaknesses


WITHIN 15 DAYS

Department asset mapping

Access review

Supplier identification

Identify sensitive information

Identify critical IT/OT dependencies

Identify existing evidence

Identify major gaps


WITHIN 30 DAYS

Close quick-win gaps

Review access controls

Review visitor controls

Review removable-media controls

Review supplier access

Review incident-reporting process

Establish evidence repository


WITHIN 60 DAYS

Conduct departmental self-assessment

Conduct mock TISAX interviews

Conduct tabletop incident exercise

Review corrective actions

Validate evidence

Verify effectiveness


90 DAYS

Organization-wide readiness review

Management review

Corrective-action verification

Supplier-security review

IT/OT review

Internal assessment


ONGOING

MONTHLY

Access review

Security incidents

New assets

New suppliers

Corrective actions

QUARTERLY

Mock assessment

Incident exercise

Supplier review

Privileged access review

ANNUALLY

Risk review

Policy review

Training

Business continuity exercise

Internal audit

Management review


THE PARTICIPANT'S 30-60-90 CARD

Give each participant a single-page card:

MY TISAX ACTION PLAN

My Department:



My Information Assets:











My Top 3 Risks:







My 3 Immediate Actions:







15-Day Action:



30-Day Action:



60-Day Action:



My Evidence Owner:



My Manager:





FINAL ACTIVITY

“TISAX COMMITMENT WALL”

Every participant writes:

“From today, I will protect __________ by __________.”

Examples:

“I will protect engineering drawings by using only approved systems.”

“I will protect production systems by not connecting unauthorized devices.”

“I will protect customer information by following need-to-know access.”

“I will report suspicious incidents immediately.”



THE FINAL MODEL

I recommend ending the program with this visual:

TISAX WORKPLACE IMPLEMENTATION CYCLE

IDENTIFY

What information do we have?

CLASSIFY

How important/sensitive is it?

CONTROL

Who can access it?

PROTECT

What controls are required?

MONITOR

Is the control working?

ASSESS

Can we demonstrate conformity?

CORRECT

What gaps must be closed?

VERIFY

Has the corrective action worked?

IMPROVE

How do we prevent recurrence?

CONTINUOUS IMPROVEMENT



A VERY IMPORTANT TRAINER POINT

I would make one distinction explicit throughout the program:

TISAX is not simply “cybersecurity awareness training.”

The ENX handbook describes TISAX as a process for proving a defined level of information-security management to partners, and its assessment process involves scope, assessment objectives, ISA-based self-assessment, assessment, findings, corrective actions, follow-up and exchange of results.

Therefore, the participants should finish the two days not merely knowing what TISAX means, but being able to answer:

“What information do I handle, what can go wrong, what controls protect it, what evidence proves the controls exist, and what action will I take in my work area tomorrow?”

 

No comments:

Post a Comment