In today’s connected automotive industry, protecting information is as critical as protecting the product itself. This two-day program introduces participants to the TISAX® framework, VDA ISA requirements, assessment process and information-security practices relevant to automotive manufacturing.
Through real-world automotive scenarios, hands-on exercises, mock assessments, case studies and workplace activities, participants will learn how to identify sensitive information, assess risks, strengthen controls, respond to incidents and prepare meaningful evidence for assessment.
The program moves beyond awareness to focus on one practical question:
“What can I do in my workplace today to protect information, strengthen trust and support TISAX readiness?”
The course follows the TISAX journey of Registration → Assessment → Exchange, as structured in the ENX TISAX Participant Handbook.
Training theme
“Protect the Information. Protect the Process. Protect
the Product. Protect the Customer.”
1. The Design of the 2-Day Program
70:30 model: 30% Concepts + 70% Activities / Case
Studies / Simulations / Workplace Application
The entire two days can revolve around one continuous
fictional automobile-manufacturing company:
“Ansari Auto Systems Pvt. Ltd.”
Participants become the company's:
- Engineering
team
- Production
team
- IT
team
- OT/Automation
team
- Quality
team
- Purchase
team
- HR
team
- Security
team
- Management
team
Their mission:
“An OEM customer has asked ANSARI Auto Systems to
demonstrate a defined level of information-security management through TISAX.”
The three major TISAX steps as Registration → Assessment
→ Exchange.
DAY 1
UNDERSTAND – IDENTIFY – CLASSIFY – PROTECT
9:00–9:30
SESSION 1 – Opening: Why Does TISAX Matter?
Learning objectives
Participants understand:
- Why
automotive companies require information-security assurance
- What
TISAX is
- Why
OEMs ask suppliers to demonstrate information security
- Why
information security is not just an IT responsibility
- Relationship
between information security and manufacturing continuity
The handbook explains that TISAX enables companies to prove
that their information-security management complies with a defined level
according to the Information Security Assessment requirements and facilitates
sharing the assessment result with partners.
Opening Activity
“WHAT WOULD A COMPETITOR WANT?”
Give every table 5 minutes.
Ask:
If a competitor wanted to reproduce our next-generation
vehicle, what information would they want?
Participants list:
- CAD
- BOM
- Product
specifications
- Supplier
details
- Production
parameters
- Test
results
- Prototype
photographs
- Software
- ECU
information
- Manufacturing
process
- Quality
parameters
- Cost
information
- Customer
data
- Future
model plans
Then ask:
“Where does each piece of information exist?”
This creates the connection:
Information → Person → Process → System → Supplier → Risk
9:30–10:15
SESSION 2 – TISAX FUNDAMENTALS
Content
Explain:
TISAX
Trusted Information Security Assessment Exchange
↓
VDA ISA (stands for Verband der Automobilindustrie
Information Security Assessment (in German: Verband der Automobilindustrie -
Informationssicherheits-Assessment). In English, it translates to the
German Association of the Automotive Industry Information Security Assessment)
Information Security Assessment
↓
Assessment Objectives
↓
Assessment
↓
TISAX Labels
↓
Exchange of Assessment Results
The handbook specifically identifies the ISA as the basis
for defined information-security requirements and explains that the handbook is
intended to help participants navigate the TISAX process.
Activity (Give participants cards) – “TISAX
Jigsaw”
- OEM
requirement
- Scope
- Assessment
objective
- Protection
need
- ISA
- Self-assessment
- Audit
provider
- Initial
assessment
- Finding
- Corrective
action
- Follow-up
- TISAX
label
- Exchange
Teams must construct the process.
10:15–10:30
BREAK
10:30–11:30
SESSION 3 – THE TISAX JOURNEY
Registration → Assessment → Exchange
Stage 1 – Registration
Participants understand:
- Participant
- Scope
- Locations
- Contacts
- Assessment
objectives
- Protection
needs
- Assessment
levels
The handbook has extensive guidance on registration
preparation, assessment scope, scope description, standard scope, scope
tailoring, locations, contacts and publication/sharing.
Hands-On Exercise Give each group:
“CREATE YOUR TISAX SCOPE”
ANSARI Auto Systems
Locations:
- Corporate
office
- R&D
centre
- Manufacturing
plant
- Warehouse
- Testing
facility
Participants determine:
What should be inside the assessment scope?
What should be outside?
Which locations process sensitive information?
Which locations need further investigation?
WORKSHEET 1
TISAX Scope Identification
|
Location |
Activity |
Information handled |
Systems |
Sensitive information? |
Include in scope? |
Reason |
|
R&D |
CAD |
Product design |
PLM |
Yes |
||
|
Plant |
Production |
Process data |
MES |
Yes |
||
|
Warehouse |
Logistics |
Dispatch data |
ERP |
|||
|
HR |
Employee records |
Personal data |
HRMS |
11:30–12:30
SESSION 4 – ASSESSMENT OBJECTIVES & PROTECTION NEEDS
This is an important area that should not be diluted into
generic cybersecurity terminology.
The handbook identifies assessment objectives such as:
- Confidential
- Strictly
confidential
- High
availability
- Very
high availability
- Prototype
parts
- Prototype
vehicles
- Test
vehicles
- Protection
of prototypes during events/photo shoots
- Data
- Special
data
and explains that assessment objectives are a key input to
the TISAX assessment process.
Activity – “WHICH OBJECTIVE?”
Give teams scenarios.
Scenario 1 - A new vehicle prototype is being tested.
Scenario 2 - Highly sensitive CAD data is exchanged
with an OEM.
Scenario 3 - Production information must remain
available to support manufacturing.
Scenario 4 - Prototype components are displayed at an
event.
Scenario 5 - A supplier processes personal data on
behalf of the organization.
Teams identify which assessment-objective concepts are
relevant.
Important trainer note
Do not
ask participants to decide their organization's actual TISAX assessment
objectives during a general awareness session. Explain that actual selection is
an organizational/TISAX scoping decision.
12:30–1:15
LUNCH
1:15–2:15
SESSION 5 – INFORMATION ASSETS & CLASSIFICATION
“If You Don't Know What You Have, You Cannot Protect It.”
Participants identify:
Physical information
- Drawings
- Printed
reports
- Prototype
documents
- Manuals
- Visitor
registers
Digital information
- CAD
- ERP
- MES
- QMS
- PLM
- Emails
- Databases
- Source
code
- Cloud
systems
Manufacturing information
- PLC
configurations
- Robot
programs
- Machine
parameters
- Process
sheets
- Production
schedules
- Quality
parameters
HANDS-ON ACTIVITY
“INFORMATION ASSET HUNT”
Give each team 20 minutes to walk mentally through their own
department.
They identify:
5 critical information assets
For each:
- Owner
- Location
- User
- Classification
- Business
impact
- Security
risk
- Existing
control
WORKSHEET 2 – ASSET REGISTER
|
Asset |
Owner |
Location |
Who uses it? |
Protection need |
Existing control |
Gap |
|
CAD files |
Engineering |
PLM |
Design team |
Very high |
||
|
Production schedule |
Production |
MES |
Production |
High |
||
|
PLC programme |
Automation |
OT server |
Maintenance |
High |
||
|
Supplier database |
Purchase |
ERP |
Purchase |
High |
2:15–3:00
SESSION 6 – ISA: CONTROL QUESTIONS & REQUIREMENTS
The handbook explains that the ISA contains three
criteria catalogues:
- Information
Security
- Prototype
Protection
- Data
Protection
and that these contain control questions and associated
requirements.
Activity – “THE TISAX QUESTION”
Give teams a control question scenario:
“How do you control access to confidential engineering
information?”
Participants must answer:
1. What is our policy?
2. What is our process?
3. Who is responsible?
4. What system enforces it?
5. What evidence exists?
6. How do we know it works?
The Golden TISAX Evidence Model
Teach participants:
POLICY - What do we say?
↓
PROCESS - What do we do?
↓
IMPLEMENTATION - How is it actually performed?
↓
EVIDENCE - What proves it?
↓
EFFECTIVENESS - How do we know it works?
3:00–3:15
BREAK
3:15–4:00
SESSION 7 – SELF-ASSESSMENT & MATURITY
The handbook specifically addresses:
- Criteria
catalogues
- Chapters
- Control
questions
- Self-assessment
fields
- Objectives
- Requirements
- Maturity
levels
- Conducting
the self-assessment
- Interpreting
the result.
Hands-On Exercise
“RED – AMBER – GREEN”
Participants take 10 simulated controls.
For each:
🟢 Implemented
🟡
Partially implemented
🔴
Not implemented
Then they must answer:
“What evidence do you have?”
This prevents the common mistake of confusing:
“We have a policy”
with
“The control is actually implemented and effective.”
Yes. I recommend running this as a 60–75 minute TISAX
self-assessment simulation, rather than simply asking participants to
choose red/amber/green.
One important distinction: Red–Amber–Green is a training
simplification, not the TISAX/ISA maturity-scale itself. The TISAX
Participant Handbook describes six maturity levels, from 0 – Incomplete
through 5 – Optimizing, and participants assess the current state for
each applicable control question. The exercise can therefore teach participants
the thinking process behind the formal self-assessment without
pretending that RAG is the official scoring method.
How to conduct the activity
Activity title
RED – AMBER – GREEN: “SHOW ME THE EVIDENCE!”
Recommended duration: 60–75 minutes
Team size
4–6 participants per team
Materials
Prepare:
- 10
control cards per team
- Red
/ Amber / Green cards
- Evidence
cards
- A3
worksheet
- Sticky
notes
- Marker
pens
- Timer
- Optional
laptop/projector
STEP 1 – Set the scenario
Tell participants:
“You are the TISAX readiness team of an automobile
manufacturing plant. An OEM customer has requested evidence that your
information-security management is appropriately implemented. You are
conducting a preliminary self-assessment.”
Then give them the rule:
Do not answer based on what you believe should happen.
Answer based on:
“What is actually happening in our workplace, and what
evidence can we produce?”
This is consistent with the handbook's approach that the
self-assessment is based on the current state of the information-security
management system, with participants determining the maturity level for
each applicable question.
STEP 2 – Give each team the 10 simulated controls
These should be training scenarios, not presented as
verbatim TISAX/ISA control wording.
CONTROL CARD 1 – ACCESS CONTROL
Situation
Only authorized employees should access confidential
engineering and CAD information.
Ask the team:
Is this:
🟢 Implemented
🟡
Partially implemented
🔴
Not implemented?
Then ask:
“Show me the evidence.”
Possible evidence
- Access-control
policy
- User-access
list
- Authorization
records
- Role
matrix
- Access
review records
- System
screenshots
- Approval
records
Challenge question
“Can you show me evidence that the control is actually
operating?”
CONTROL CARD 2 – JOINER / MOVER / LEAVER
Situation
When an employee joins, changes role or leaves, their system
access is appropriately created, modified or removed.
Evidence could include:
- HR
notification
- IT
ticket
- Access
request
- Approval
record
- Deactivation
record
- Exit
checklist
- Periodic
access review
Killer question
“Can you prove that someone who left six months ago no
longer has access?”
This usually creates excellent discussion.
CONTROL CARD 3 – INFORMATION CLASSIFICATION
Situation
Confidential engineering information is identified and
handled according to its protection requirements.
Evidence
- Information-classification
policy
- Classification
labels
- Document
examples
- Employee
training
- Data-handling
procedure
- System
configuration
Challenge
Show participants two documents:
A: Public company brochure
B: New vehicle CAD drawing
Ask:
“Should they be handled in the same way?”
CONTROL CARD 4 – SUPPLIER ACCESS
Situation
External suppliers receive only the access required for
their approved business activity.
Evidence
- Supplier
agreement
- NDA
- Access
approval
- VPN
records
- User
list
- Access
review
- Contractual
security requirements
- Termination
records
Challenge
“Supplier X has completed its project. Who ensures its
access is removed?”
CONTROL CARD 5 – VISITOR MANAGEMENT
Situation
Visitors and contractors entering restricted areas are
identified, authorized and appropriately controlled.
Evidence
- Visitor
register
- ID
verification
- Visitor
badge
- Escort
records
- NDA
- Restricted-area
procedure
- CCTV/access-control
records
Scenario
A supplier engineer says:
“I forgot my ID, but your production manager knows me.”
Ask:
“Do we let him in?”
CONTROL CARD 6 – USB / REMOVABLE MEDIA
Situation
Removable media is controlled to reduce unauthorized
transfer of information or introduction of malicious software.
Evidence
- USB
policy
- Endpoint
configuration
- Approved-device
list
- Exception
approval
- USB
activity logs
- Awareness
records
Scenario
A maintenance engineer brings a personal USB containing a
machine configuration file.
Ask:
“What should happen?”
CONTROL CARD 7 – INCIDENT REPORTING
Situation
Employees know how to report suspected information-security
incidents and incidents are handled through a defined process.
Scenario
An employee accidentally sends a confidential drawing to the
wrong email address.
Ask:
“What should the employee do in the first five minutes?”
Evidence
- Incident-response
procedure
- Incident
reporting form
- Ticket
- Incident
register
- Escalation
matrix
- Training
records
- Previous
incident records
CONTROL CARD 8 – BACKUP & RECOVERY
Situation
Critical information is backed up and recovery capability is
periodically verified.
Evidence
- Backup
policy
- Backup
schedule
- Backup
logs
- Recovery
test records
- Restore
evidence
- Backup
monitoring
- Business
continuity documentation
Killer question
“You say we have backups. Show me evidence that we have
successfully restored from one.”
This teaches the difference between:
Backup exists
and
Recovery capability has been demonstrated.
CONTROL CARD 9 – PROTOTYPE PROTECTION
Situation
Prototype vehicles and components are protected from
unauthorized access, photography and disclosure.
Scenario
A contractor takes a photograph inside the prototype area.
Ask:
“What controls should have prevented this?”
Evidence
- Prototype
protection procedure
- Restricted-area
access
- Photography
policy
- Visitor
controls
- NDA
- Security
briefing
- CCTV/access
logs
- Incident
records
This connects particularly well with the TISAX
prototype-protection assessment objectives described in the handbook.
CONTROL CARD 10 – SECURITY AWARENESS
Situation
Employees receive appropriate information-security awareness
and the organization maintains evidence of that activity.
Evidence
- Training
calendar
- Attendance
- LMS
records
- Assessment
results
- Awareness
campaigns
- Phishing
simulation results
- Refresher
training records
Killer question
“You conducted training last year. How do you know employees
actually understood it?”
STEP 3 – The RAG Decision
Give teams three cards:
🟢 GREEN
IMPLEMENTED
The control appears to be implemented and the team can
identify credible evidence.
🟡 AMBER
PARTIALLY IMPLEMENTED
Something exists, but there is a gap.
Examples:
- Policy
exists but employees don't consistently follow it.
- Access
review occurs but not for all systems.
- Training
occurs but evidence is incomplete.
- Supplier
controls exist for some suppliers but not others.
🔴 RED
NOT IMPLEMENTED / NOT DEMONSTRABLE
The control is absent, ineffective or the team cannot
demonstrate that it is implemented.
Important trainer point
Don't automatically equate:
“We can't find the evidence”
with
“The control doesn't exist.”
Instead ask:
“Who owns the evidence, where should it exist, and can it
be demonstrated?”
That distinction is important in a real assessment.
STEP 4 – THE MOST IMPORTANT QUESTION
After every RAG decision, the trainer asks:
“SHOW ME THE EVIDENCE.”
This should become the signature phrase of the exercise.
For example:
Participant:
“Green. We have access control.”
Trainer:
“Show me the evidence.”
Participant:
“We have an access-control policy.”
Trainer:
“That's evidence that a policy exists. Show me evidence
that the control is implemented.”
Then:
“Show me evidence that it is working.”
This creates the learning breakthrough.
STEP 5 – Introduce the 5 Evidence Questions
For every control, ask:
1. WHAT?
What control exists?
2. WHO?
Who owns it?
3. HOW?
How is it implemented?
4. WHERE?
Where is the evidence?
5. HOW DO YOU KNOW?
How do you know it is effective?
STEP 6 – Add the “EVIDENCE CARD” GAME
This makes the activity much more interactive.
Prepare evidence cards such as:
Evidence cards
- Policy
document
- Procedure
- Training
attendance
- Access-control
list
- Approval
email
- System
screenshot
- Audit
report
- Log
file
- Incident
record
- Visitor
register
- CCTV
record
- Contract
- NDA
- Backup
log
- Recovery-test
report
- Risk
assessment
- KPI
report
- Management
review
- Corrective-action
record
Mix them up.
Teams must select the most appropriate evidence for
each control.
Example
Control:
Supplier access is controlled.
Team chooses:
❌ Company brochure
❌
Employee attendance sheet
❌
General cybersecurity policy
But selects:
✅ Supplier access approval
✅
Supplier contract
✅
VPN access record
✅
User-access list
✅
Periodic access review
Then ask:
“Which piece of evidence would be strongest?”
Now the participants are thinking like assessors.
STEP 7 – Introduce “POLICY vs PRACTICE vs EVIDENCE”
Put this on the screen:
LEVEL 1
POLICY
“We have a procedure.”
⬇
LEVEL 2
PRACTICE
“People actually follow the procedure.”
⬇
LEVEL 3
EVIDENCE
“We can demonstrate that it is being followed.”
⬇
LEVEL 4
EFFECTIVENESS
“We can demonstrate that it achieves its objective.”
This is an especially important discussion because the
handbook explains that ISA requirements need to be interpreted in the context
and spirit of the objective, and that the audit provider considers the
organization's actual implementation.
STEP 8 – Give Them the Scoring Sheet
TISAX RAG SELF-ASSESSMENT WORKSHEET
|
# |
Simulated Control |
RAG |
What evidence exists? |
Evidence owner |
Gap |
Immediate action |
|
1 |
Access control |
🟢 |
||||
|
2 |
Joiner/Mover/Leaver |
🟡 |
||||
|
3 |
Classification |
🔴 |
||||
|
4 |
Supplier access |
|||||
|
5 |
Visitor management |
|||||
|
6 |
USB control |
|||||
|
7 |
Incident reporting |
|||||
|
8 |
Backup/recovery |
|||||
|
9 |
Prototype protection |
|||||
|
10 |
Awareness |
STEP 9 – The “AUDITOR ATTACK” ROUND
Now make the exercise more challenging.
Tell participants:
“The auditor is not satisfied with your first answer.”
For every Green answer, ask one of these:
Auditor Question 1
“Show me the document.”
Auditor Question 2
“Show me a recent record.”
Auditor Question 3
“Who owns this control?”
Auditor Question 4
“How frequently is it reviewed?”
Auditor Question 5
“Show me what happens when the control fails.”
Auditor Question 6
“How do you know employees follow it?”
Auditor Question 7
“What happened during the last review?”
Auditor Question 8
“Can you demonstrate effectiveness?”
This is where the exercise becomes powerful.
STEP 10 – Convert RED/AMBER into Corrective Actions
After all 10 controls have been assessed, tell teams:
“You have 20 minutes to turn your Amber and Red findings
into an action plan.”
Use:
|
Finding |
Root cause |
Corrective action |
Owner |
Deadline |
Evidence of closure |
|
USB control weak |
No formal process |
Establish approved USB procedure |
IT |
15 days |
Policy + configuration |
|
Supplier access not reviewed |
No periodic review |
Quarterly access review |
IT/Purchase |
30 days |
Review report |
|
Visitor controls inconsistent |
Process varies by gate |
Standardize procedure |
Security |
15 days |
Checklist + records |
STEP 11 – Connect It to Actual TISAX Maturity
Now reveal the formal concept.
Tell participants:
“Our Red/Amber/Green exercise is only a learning tool. In
the actual ISA self-assessment, maturity is evaluated using six maturity
levels.”
|
ISA Level |
Simplified interpretation |
|
0 |
Incomplete |
|
1 |
Performed |
|
2 |
Managed |
|
3 |
Established |
|
4 |
Predictable |
|
5 |
Optimizing |
The handbook provides these informal descriptions and
explains that maturity is rated per question in the self-assessment.
Then ask:
Green doesn't automatically mean “Level 5.”
This is an important learning point.
A control may be operating but still not be mature,
systematically managed, monitored or continuously improved.
STEP 12 – Final Debrief
Ask every team:
Question 1 - Which control did you initially mark Green
but later discover had weak evidence?
Question 2 - Which control became Amber after the auditor
questions?
Question 3 - Which control became Red?
Question 4 - What evidence was hardest to produce?
Question 5 - Who actually owns the evidence?
Question 6 - What can you fix within 15 days?
THE BIG TAKEAWAY
Put this on the final slide:
DON'T SAY:
“We have a policy.”
SAY:
“Here is our requirement.”
“Here is our process.”
“Here is the evidence.”
“Here is the owner.”
“Here is how we monitor it.”
“Here is how we know it is effective.”
That is the mindset you want participants to carry back to
the automobile plant.
The handbook itself emphasizes that the self-assessment
evaluates the current state of the information-security management system and
that the assessment ultimately checks whether applicable requirements conform.
Trainer's final challenge
End with:
“If an auditor walked into your department tomorrow
morning and asked: ‘Show me the evidence’ — what would you be able to produce
in five minutes?”
That
question will make the activity memorable and immediately applicable.
4:00–4:45
SESSION 8 – AUTOMOTIVE CASE STUDY
CASE: “THE LEAKED CAD FILE”
Situation
A design engineer receives a WhatsApp message:
“The supplier's email isn't working. Please send the latest
drawing here.”
The engineer sends it.
Three days later:
The supplier reports that the drawing has appeared outside
the approved organization.
Teams investigate
What went wrong?
- Unauthorized
channel
- Lack
of verification
- Information
classification failure
- Supplier-control
weakness
- Human-factor
failure
- Potential
contractual issue
Teams develop:
Immediate action
Containment
Investigation
Reporting
Corrective action
Preventive action
4:45–5:15
SESSION 9 – MOVIE-BASED LEARNING
Use short clips only, followed by structured
discussion.
Bollywood / Indian cinema options
Special 26
Theme:
Identity verification / impersonation / trust
Question:
“Does looking official make someone authorized?”
Raazi
Theme:
Need-to-know / information secrecy / communication
discipline
Question:
“Who really needs to know sensitive information?”
A Wednesday!
Theme:
Crisis communication / information / decision-making
Question:
“What happens when information is incomplete and time is
limited?”
2.0
Theme:
Connected technology / digital dependency
Question:
“What happens when connected systems become part of a wider
attack surface?”
5:15–5:30
DAY 1 REFLECTION
Every participant completes:
“3–2–1”
3 things I learned
2 risks I identified in my work
1 action I will implement tomorrow
DAY 2
ASSESS – RESPOND – RECOVER – IMPROVE
9:00–9:45
SESSION 10 – TISAX ASSESSMENT PROCESS
The handbook identifies three TISAX assessment types:
- Initial
assessment
- Corrective
action plan assessment
- Follow-up
assessment
The initial assessment always occurs; the other two may
occur depending on findings and corrective actions.
ROLE PLAY
“YOU ARE BEING ASSESSED”
Roles:
- Auditor
- IT
manager
- Engineering
manager
- HR
- Production
manager
- Security
- Observer
Auditor asks:
“Show me how access to confidential engineering information
is controlled.”
The manager must demonstrate:
Requirement → Process → Evidence → Effectiveness
9:45–10:30
SESSION 11 – FINDINGS & CONFORMITY
Teach the concept of conformity.
The handbook explains that the assessment checks applicable
requirements individually and distinguishes different types of findings, with
the overall assessment result potentially being conform, minor non-conform
or major non-conform.
Activity – “AUDITOR FINDING”
Give participants examples.
Finding A - Policy exists but has not been reviewed.
Finding B - Access rights exist for an employee who
left months ago.
Finding C - Critical security control is absent.
Teams identify:
- What
is the problem?
- What
is the root cause?
- What
evidence would the auditor need?
- What
corrective action is appropriate?
10:30–10:45
BREAK
10:45–11:45
SESSION 12 – CORRECTIVE ACTION PLAN
This should be one of the most practical sessions.
The handbook explains that corrective actions should address
the root cause, critical risks should be appropriately mitigated, and
implementation periods must be appropriate.
WORKSHEET 3
Corrective Action Plan
|
Finding |
Root cause |
Immediate containment |
Corrective action |
Owner |
Deadline |
Evidence |
Effectiveness verification |
|
Shared account |
Poor access design |
Disable account |
Create individual accounts |
IT |
|||
|
Supplier access |
No review process |
Suspend access |
Quarterly review |
IT/Supplier |
|||
|
Uncontrolled USB |
No procedure |
Block device |
Implement removable-media control |
IT |
11:45–12:30
SESSION 13 – FOLLOW-UP ASSESSMENT
Explain:
Initial Assessment
↓
Findings
↓
Corrective Action
↓
Follow-up Assessment
↓
Resolution
The handbook states that the purpose of the follow-up
assessment is to determine whether previously identified non-conformities have
been resolved.
Activity
“CLOSE THE FINDING”
Each team receives a finding.
They must produce:
- Root
cause
- Corrective
action
- Evidence
- Effectiveness
measure
- Closure
criteria
12:30–1:15
LUNCH
1:15–2:15
SESSION 14 – IT/OT & SHOPFLOOR SECURITY
“WHEN CYBERSECURITY STOPS THE FACTORY”
Map:
Corporate IT
↓
Plant IT
↓
MES
↓
SCADA
↓
PLC
↓
Robot
↓
Machine
↓
Product
REALISTIC CASE STUDY
8:30 AM - Production line starts.
8:45 - MES becomes unavailable.
9:00 - Operator reports abnormal machine behaviour.
9:15 - Maintenance discovers an unauthorized USB.
9:30 - IT detects suspicious network traffic.
10:00 - Production management wants to continue.
TEAM TASK
Determine:
Who acts?
Who decides?
Who communicates?
What is isolated?
What evidence is preserved?
What production activity can safely continue?
What must stop?
WORKSHEET 4
IT/OT Dependency Map
|
Process |
System |
OT dependency |
Criticality |
Manual fallback |
Owner |
|
Production planning |
ERP/MES |
||||
|
Welding |
PLC |
||||
|
Inspection |
QMS |
||||
|
Dispatch |
ERP |
2:15–3:00
SESSION 15 – SUPPLIER & THIRD-PARTY SECURITY
Participants map:
OEM
↓
Tier 1
↓
Tier 2
↓
Tier 3
↓
Logistics
↓
Service providers
CASE STUDY
A supplier has:
- Remote
access
- Engineering
data
- VPN
- Contractor
access
- Shared
accounts
- No
documented access review
Team task
Build a supplier-security action plan.
SUPPLIER CHECKLIST
☐ NDA
☐ Information classification
☐ Security requirements
☐ Access approval
☐ MFA
☐ Remote access control
☐ User lifecycle
☐ Incident notification
☐ Data return/deletion
☐ Backup/recovery
☐ Periodic review
☐ Contract termination controls
3:00–3:15
BREAK
3:15–4:00
SESSION 16 – TISAX INCIDENT RESPONSE WAR ROOM
Scenario: “THE 9:00 AM INCIDENT”
A ransomware-like incident has affected:
- Engineering
server
- Production
workstation
- Shared
drive
- MES
connectivity
A supplier calls saying:
“We have received a suspicious engineering file from your
organization.”
Participants have 30 minutes.
They must produce:
1. Immediate containment
2. Incident notification
3. Evidence preservation
4. Business continuity
5. Supplier communication
6. Management communication
7. Recovery
8. Lessons learned
INCIDENT LOG
|
Time |
Event |
Action |
Owner |
Evidence |
Decision |
|
09:00 |
|||||
|
09:10 |
|||||
|
09:20 |
|||||
|
09:30 |
4:00–4:45
SESSION 17 – MOCK TISAX ASSESSMENT
This is the capstone exercise.
Create five audit stations:
Station 1 - Information Security
Station 2 - Prototype Protection
Station 3 - Data Protection
Station 4 - Physical / IT / OT Security
Station 5 - Supplier & Incident Management
The ISA handbook structure includes these three criteria
catalogues: information security, prototype protection and data protection.
MOCK AUDIT QUESTION BANK
Information Security
How do you classify information?
How do you control access?
How do you remove access when an employee leaves?
How do you manage incidents?
How do you manage suppliers?
Prototype Protection
Who can access prototype areas?
Can employees photograph prototypes?
How are visitors controlled?
How are prototype documents protected?
Data Protection
Who processes personal data?
Why do they have access?
How is access controlled?
How is information retained/deleted?
4:45–5:15
SESSION 18 – THE TISAX IMPLEMENTATION ROADMAP
TODAY
☐ Identify 5 critical
information assets
☐ Identify their owners
☐ Review your own access
☐ Stop unauthorized
information-sharing channels
☐ Report security weaknesses
WITHIN 15 DAYS
☐ Department asset mapping
☐ Access review
☐ Supplier identification
☐ Identify sensitive information
☐ Identify critical IT/OT
dependencies
☐ Identify existing evidence
☐ Identify major gaps
WITHIN 30 DAYS
☐ Close quick-win gaps
☐ Review access controls
☐ Review visitor controls
☐ Review removable-media
controls
☐ Review supplier access
☐ Review incident-reporting
process
☐ Establish evidence repository
WITHIN 60 DAYS
☐ Conduct departmental
self-assessment
☐ Conduct mock TISAX interviews
☐ Conduct tabletop incident
exercise
☐ Review corrective actions
☐ Validate evidence
☐ Verify effectiveness
90 DAYS
☐ Organization-wide readiness
review
☐ Management review
☐ Corrective-action verification
☐ Supplier-security review
☐ IT/OT review
☐ Internal assessment
ONGOING
MONTHLY
☐ Access review
☐ Security incidents
☐ New assets
☐ New suppliers
☐ Corrective actions
QUARTERLY
☐ Mock assessment
☐ Incident exercise
☐ Supplier review
☐ Privileged access review
ANNUALLY
☐ Risk review
☐ Policy review
☐ Training
☐ Business continuity exercise
☐ Internal audit
☐ Management review
THE PARTICIPANT'S 30-60-90 CARD
Give each participant a single-page card:
MY TISAX ACTION PLAN
My Department:
My Information Assets:
My Top 3 Risks:
My 3 Immediate Actions:
15-Day Action:
30-Day Action:
60-Day Action:
My Evidence Owner:
My Manager:
FINAL ACTIVITY
“TISAX COMMITMENT WALL”
Every participant writes:
“From today, I will protect __________ by __________.”
Examples:
“I will protect engineering drawings by using only approved
systems.”
“I will protect production systems by not connecting
unauthorized devices.”
“I will protect customer information by following
need-to-know access.”
“I will report suspicious incidents immediately.”
THE FINAL MODEL
I recommend ending the program with this visual:
TISAX WORKPLACE IMPLEMENTATION CYCLE
IDENTIFY
↓
What information do we have?
CLASSIFY
↓
How important/sensitive is it?
CONTROL
↓
Who can access it?
PROTECT
↓
What controls are required?
MONITOR
↓
Is the control working?
ASSESS
↓
Can we demonstrate conformity?
CORRECT
↓
What gaps must be closed?
VERIFY
↓
Has the corrective action worked?
IMPROVE
↓
How do we prevent recurrence?
↺ CONTINUOUS IMPROVEMENT
A VERY IMPORTANT TRAINER POINT
I would make one distinction explicit throughout the
program:
TISAX is not simply “cybersecurity awareness training.”
The ENX handbook describes TISAX as a process for proving a
defined level of information-security management to partners, and its
assessment process involves scope, assessment objectives, ISA-based
self-assessment, assessment, findings, corrective actions, follow-up and
exchange of results.
Therefore, the participants should finish the two days not
merely knowing what TISAX means, but being able to answer:
“What information do I handle, what can go wrong, what
controls protect it, what evidence proves the controls exist, and what action
will I take in my work area tomorrow?”
No comments:
Post a Comment