Prepare an automotive information security assessment around partner requirements, assessment scope, and an operational ISMS.
Clarify the partner request
Ask the customer which assessment objectives, scope, locations, and sharing arrangement it expects. The ENX participant handbook describes registration, selection of an audit provider, the assessment, and sharing the result with a partner. It is an assessment process, not a general certificate that covers every site or service automatically.
Confirm the current Information Security Assessment questionnaire and version before building a gap analysis. ENX publishes current and upcoming ISA materials, and a future version should not be treated as the current assessment basis.
Map sites, information, and processes
Identify the facilities, teams, systems, prototypes, and customer information that fall within the requested scope. Include outsourced IT and physical handling paths where they support in-scope activity. Decide who owns security governance, access, supplier oversight, incident response, and evidence at each location.
A supplier already operating an ISO/IEC 27001 ISMS may reuse much of its governance and control evidence. Check the exact TISAX assessment objectives and scope instead of assuming equivalence.
Test evidence with the people doing the work
Complete a documented self-assessment against the applicable ISA, then sample access grants, visitor records, supplier reviews, incidents, vulnerability handling, and training as appropriate to the requested objectives. Record gaps, owners, remediation dates, and how closure will be verified. A written policy without a repeatable process will be difficult to defend.
Plan enough operating time for controls to generate real records before the independent assessment.
Preserve assessment independence
Consulting can help scope the work and prepare processes and evidence. ENX-approved audit providers conduct TISAX assessments and issue the resulting report and labels. Agree sharing with the customer through the TISAX process rather than publishing an unsupported assurance claim.
After the assessment, treat findings and partner feedback as inputs to the supplier’s ongoing security program.
Put it into practice
- Confirm partner-required objectives, sites, and sharing route.
- Use the current applicable ISA questionnaire.
- Sample evidence across all in-scope locations and suppliers.
- Keep advisory work separate from the ENX audit provider’s assessment.
Primary sources
- ENX: TISAX Participant Handbook
- ENX: TISAX download center and ISA materials
- ISO: ISO/IEC 27001 information security management
Normstone resources are general information, not legal advice or an independent assessment.