CRA Cybersecurity ECS Educational General News

Cyber Resilience Act Single Reporting Platform (CRA-SRP) obligations for software companies selling globally

I wrote here about the CRA and the deployment plan: https://www.sorinmustaca.com/eu-cyber-resilience-act-cra-overview/  We are past September 11th and the Art. 14 of CRA is applying. Who is affected? Is a a company from a non EU country, which sells software globally affected by the CRA Art. 14? Any company is affected if the software is made […]

Article Certification Cybersecurity ECS Educational Security TISAX

ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance

This is the part 5 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1).   ISA VDA 6.0.3 (part 5) — Information Security Sheet: Supplier Relationships, Compliance   Chapter 6 — Supplier Relationships This chapter addresses how the organization manages information security risks arising […]

Article Certification Cybersecurity ECS Educational Security TISAX

ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management

This is the part 3 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1).   ISA VDA 6.0.3 (part 3) — Information Security Sheet: Human Resources, Physical Security, Identity and Access Management Chapter 2 — Human Resources This chapter addresses the people dimension of […]

Article Cybersecurity ECS Educational News Security TISAX

ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization

This is the part 2 of the series about the TISAX label: TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1).   ISA VDA 6.0.3 (part 2) — Information Security Sheet: IS Policies and Organization   Chapter 1 — IS Policies and Organization This chapter establishes the governance foundation of the […]

Cybersecurity ECS Educational News Security TISAX

TISAX getting started: A Deep Dive into the ISA Assessment Workbook (part 1)

  TISAX — the Trusted Information Security Assessment Exchange — or Trusted ISA Exchange – is the automotive industry’s answer to a decades-old problem: every OEM was running its own supplier security questionnaire, and tier-1 and tier-2 suppliers were drowning in redundant audits. ENX Association, backed by the VDA (Verband der Automobilindustrie), formalized the exchange […]