Logo_100yearsAfnor_CMYK_White

TISAX®, the cybersecurity assessment specific to the automotive sector

Facebook
Email
Twitter
LinkedIn
Agri-food expertise

When it comes to automotive cybersecurity, we're moving up a gear. In a fiercely competitive environment at the cutting edge of innovation, the automotive giants are becoming increasingly aware of the risks of hacking and leaks resulting from the digitalization of processes and exchanges. How do you protect the plans for a prototype when it is ready to be manufactured by a subcontractor? How can we ensure the security of confidential plans stored on a server abroad? What protection is there against ransomware threatening to spread the secrets of a future revolutionary engine on the darkweb? How to ensure business continuity in the event of a major crisis?

Inspired byISO/IEC 27001, the TISAX® standard provides answers to these new concerns that are weighing on the entire automotive sector. The AFNOR group is now recognized by ENX, the association that owns the standard, to assess the practices and information systems of players in the sector.

Tisax®, the cybersecurity assessment specific to the automotive sector

TISAX® evaluation: a sector-specific version ofISO/IEC 27001

Initiated by the German automotive industry, including the well-known VDA(Verband der Automobilindustrie), work on TISAX® (for "Trusted Information Security Assessment Exchange") began in 2017. This private standard aims to adapt the requirements set by ISO/IEC 27001, a voluntary international standard for information systems security management, to the automotive sector. This sector is characterized by strong competition and the race for innovation, with a real risk of espionage, multiplied tenfold by the large chain of subcontractors," points out Thomas Sanjullian, Digital Confidence Product Manager at AFNOR Certification. The aim of the TISAX® assessment is to impose strict cybersecurity rules on all the players involved."

Data registry, governance, business continuity plan, employee awareness and training... TISAX® requirements vary according to the level of assessment carried out, of which there are three: a self-assessment, a remote audit by a third-party assessor, and finally an in-depth audit lasting several days on site.

TISAX® is no longer an option," says Thomas Sanjullian. Manufacturers are already including this requirement in their invitations to tender. To be able to respond and receive data from the manufacturer, they must provide proof of their level." Since September 2023, the AFNOR group has been recognized to carry out this assessment. Auditors are currently undergoing training to be able to conduct their first audits from early 2024.

> Interested in finding out more about TISAX® ?
Watch a replay of the information webinar (webinar)
Privacy Protection and Respect The processing of personal data is necessary to review your request, submitted in your capacity as a professional, to the AFNOR Group. Where applicable, this data may also be used to send you commercial information. In accordance with current European regulations, you have the right to access, rectify, erase, withdraw consent, restrict processing, object to processing, and request data portability regarding your data. These rights may be exercised by sending a message to the AFNOR DPO. French speakers: Click here. English speakers: Click here. Detailed information on the use of your data and the exercise of your rights can be found in the AFNOR Group’s Charter on the Protection of Personal Data and Privacy. Click here to read it.
=

At the same timeISO/IEC 27001the flagship standard providing guidelines for deploying a solid, efficient information management system, is experiencing unprecedented popularity. With almost twice as many people certified in two years, the rise of ISO/IEC 27001 is confirmed at global level, with almost 100,000 sites certified worldwide. In terms of countries, the top three are China, Japan and the UK. The main reason for this strong growth is the central importance of data protection issues. ISO 27001 deals with the security of information systems, and covers both digital and paper data," explains Brice Gilbert, head of ISO 27001 at AFNOR Certification. A few years ago, 62% of companies adopting this standard did so voluntarily. But with the tightening of the regulatory context, most of them are now committing themselves to compliance, so that they can continue to respond to calls for tender. Unsurprisingly, in the ISO Survey, the business sector that makes most use of ISO/IEC 27001 certification is information technology.

"Manufacturers, particularly in the aeronautics sector, are well aware of the stakes. A hack, a data leak or a ransom demand, and the company's survival is at stake. AFNOR is proposing a multi-stage strategy, starting with a free self-assessment to initiate reflection, whatever your sector of activity," says Brice Gilbert. Five years after the first version in May 2017, the publication of the updated standard in 2022, with new aspects such as the cloud, is available as an accredited certification thanks to our international network.

Read more

latest news
from the international network

Agri-food expertise
ISO 14067 Taiwan
Taiwan

"Fobao International Certification" Completes ISO 14067 Product Carbon Footprint Verification for the Department of Anesthesiology at Shuanghe Hospital

"Fabao International Certification" recently announced that the Department of Anesthesiology at "Shuanghe Hospital" has completed Taiwan's first ISO 14067:2018 product carbon footprint verification "classified by anesthesia method" and obtained a verification statement. These verification results confirm that the hospital has established a system for managing the carbon footprint of its surgical anesthesia services that complies with international standards. As an internationally recognized third-party verification body, "Fabao International Certification" conducted this verification in accordance with the ISO 14067 standard, independently assessing the carbon footprints of four anesthesia methods—endotracheal intubation, intravenous anesthesia, mask anesthesia, and spinal anesthesia—in the Anesthesiology Department of "Shuanghe Hospital." The verification process confirmed that the hospital’s data collection, emissions calculation, and management procedures comply with international standards. The verification results show that, regardless of the type of anesthesia, over 80% of carbon emissions are concentrated during the surgical anesthesia administration phase, with the primary sources being energy use and equipment operation. Operating rooms have long been the most resource-intensive units in hospitals, accounting for approximately one-quarter of the hospital’s total carbon emissions. These verification findings provide a scientific basis for precisely identifying carbon reduction targets and optimizing medical processes in the future. The professional verification team at “Fasbo International Certification” noted that healthcare institutions breaking down their carbon footprint assessments to the level of clinical operations demonstrates that sustainability management is deeply embedded in their daily operational processes. Shuanghe Hospital’s completion of this verification highlights concrete progress in the healthcare industry’s transition toward net-zero emissions. "Fasbo International Certification" has long provided product carbon footprint verification services, assisting various industries in establishing credible environmental performance data. In the future, it will continue to promote the implementation of sustainable governance goals in Taiwan’s healthcare and related industries through professional verification.

Read more "
Taiwan ISO 14067
Taiwan

"Fobao International Certification" Completes ISO 14067 Product Carbon Footprint Verification for "Yatong Hospital's" SBRT Services

"Fabao International Certification" recently announced that the Department of Radiation Oncology at "Yatong Hospital" has completed the ISO 14067:2018 product carbon footprint verification for its stereotactic body radiation therapy (SBRT) services for breast cancer and prostate cancer, and has officially been awarded a verification statement. These verification results confirm that the hospital’s carbon footprint data and management system comply with international standards. As an internationally recognized third-party verification body, "Fabao International Certification" conducted an independent assessment of the carbon footprint scope definition, data collection, calculation methods, and selection of emission factors for "Yatong Hospital’s" SBRT services in accordance with the ISO 14067 standard. The verification process confirmed that the carbon emission data for these services is complete, consistent, and transparent, and can serve as a basis for future carbon reduction management. The SBRT technology implemented by “Yatong Hospital” significantly reduces the number of treatment sessions required—which typically ranges from 20 to 39 in traditional radiation therapy—to just 5 sessions. Verification results show that through optimized electricity usage, reduced medical consumables, and minimized waste, overall carbon emissions are approximately 60% lower than those of traditional treatment regimens. This achievement also reduces the transportation burden and time costs for patients traveling to and from the hospital. The professional verification team at “Fasbo International Certification” noted that the verification of a medical service’s product carbon footprint signifies that the institution has incorporated environmental performance into its service quality management system. “Yatong Hospital” has established a carbon footprint management system compliant with international standards, creating an important practical case study for the low-carbon transition of Taiwan’s healthcare industry. “Fabao International Certification” has long provided product carbon footprint verification services, assisting various industries in establishing credible environmental performance data. In the future, it will continue to promote the implementation of sustainable transformation goals in the healthcare and related industries through professional verification.

Read more "
Taiwan

"Fobao International Certification" Completes ISO 14064-1 Greenhouse Gas Inventory Verification for "Shengjie Construction"

"Fabao International Certification" recently announced that "Shengjie Construction Co., Ltd." has successfully passed third-party verification of its ISO 14064-1:2018 greenhouse gas inventory. This verification confirms that the company's greenhouse gas emissions data and management system comply with international standards, demonstrating concrete results in institutionalizing its commitment to sustainability. As an internationally recognized third-party verification body, "Fabao International Certification" conducted an independent assessment of "Shengjie Construction’s" organizational boundaries, emission source identification, and data collection and calculation processes in accordance with the ISO 14064-1 standard. The verification process confirmed that the company has established a systematic foundation for carbon management, and that its inventory results are reliable and can serve as a basis for formulating future carbon reduction strategies. Sheng Jie Construction, a construction firm in the Taoyuan area, proactively implemented ISO 14064-1 verification and published a sustainability report despite the absence of mandatory regulatory requirements. In addition to promoting low-carbon building materials and energy-efficient designs on the environmental front, the company has long promoted a “community health check” mechanism on the social front, assisting communities where homes have already been delivered in maintaining building quality, thereby demonstrating its commitment to resident relations and the management of the building’s entire life cycle. The professional verification team at “Fasbia International Certification” noted that a company’s voluntary adoption of greenhouse gas inventory verification signifies that it views carbon management as an essential component of organizational governance. By establishing a management system compliant with international standards, “Sheng Jie Construction” has set an important practical example for the sustainable development of Taiwan’s construction industry. "Fasbia International Certification" has long provided greenhouse gas inventory verification services, assisting various industries in establishing credible environmental performance data. In the future, it will continue to promote the implementation of sustainable governance goals by Taiwanese companies through professional verification.

Read more "
Back to top