Can Adiguzel

Penetration Testing Process

Penetration Testing Process

In this blog post, we will dive into Penetration Testing Processes and explain to you each phase of Penetration Testing in detail. However, if you are new to Penetration Testing and want to learn more information about Pentesting in general, you are welcome to read this blog post.

Content:

Penetration Testing Processes define different approaches to how penetration tests are organized and conducted. There are methods for Penetration Testing to identify security vulnerabilities in an organization. Each different method describes the process that a company can take to discover these vulnerabilities. While companies can use their custom processes, many well-established, industry-recognized methods can be a great option for companies. Some organizations use these developed methodologies as an “out of the box” solution, while others use them as a foundation on which to build.

There is no doubt that regular Penetration Testing is an essential part of the vulnerability management process to reduce risk. It is important to ensure that Penetration Testing is efficient and using the correct Penetration Testing Method is an essential component of that. In this context, a methodology defines the logic according to which various test cases are carried out in order to evaluate the security of an asset.

Several Penetration Testing standards and frameworks have been published in the past. Penetration Testing Methods play a comprehensive role in benchmarking practices. For example, the OWASP Top 10 application security risks are the standard for evaluating web applications. The US Department of Commerce’s popular NIST Cyber Framework, the Open-Source Security Testing Methodology Manual, and the Pentesting Execution Standard are other methods and standards followed by organizations worldwide. OWASP, CIS benchmarks, and SANS Top 20 Critical Controls are often the most popular benchmarks for testing vulnerabilities.

Penetration Testing Processes: Types of Penetration Testing

Network Penetration Testing

A network Penetration Test identifies vulnerabilities in applications and systems by deliberately using a variety of malicious techniques to assess the network’s security or lack of response.

Like vulnerability assessments, a network Penetration Test, which may also be known as Pentest, aims to clarify vulnerabilities in a network.

There are some underlying benefits to performing network Pentest on your systems including:

  • Understanding the network baseline
  • Testing your security infrastructure and controls
  • Preventing network and data breaches
  • Ensuring network and system security

Web-Application Penetration Testing

Web application Pentesting refers to the process of preparing a hacking attack on your web application to detect and analyze vulnerabilities that an attacker could exploit. The entire web application Penetration Testing process is focused on helping you to better understand the security status of your web application whether it’s strength and resilience to a variety of cyber-attacks.

The usual process of Pentesting a web application is misconfiguration, unpatched software, SQL injection, cross-site scripting, and many more. It includes a vulnerability scanner used to detect vulnerabilities in your system, then Pentesters will manually try to confirm these vulnerabilities found by the scanner. Furthermore, manual scan can be taken one step forward by validating complex vulnerabilities such as business logic flaws.

Social Engineering Penetration Testing

Social engineering Penetration Testing is the practice of performing typical social engineering fraud attempts on an organization’s employees to determine the organization’s vulnerability to this type of exploit.

Those tests are designed to test employees’ compliance with security policies and practices set by management. Tests should tell an organization how easily an intruder could persuade employees to break security rules or reveal or divulge confidential information. The company should also get a much better understanding of how successful its safety training is and how the organization compares to its competitors in terms of safety.

Penetration Testing Process

Pre-engagement, Planning, and Objectives Agreement

The first step in the Penetration Testing Process is to create the testing plan. A properly curated plan provides a path through an organization’s complex IT structure. To begin creating a plan, one must have a complete understanding of the organization and how it operates. Knowledge of their systems and applications is also important. Once we have this information, we can proceed to build the examination scope.

Defining a precise scope of work ensures understanding and clarity of goals, exclusions, and what to do if something happens. We provide a proven project management approach is employed and ensure all parties are aware of approval forms and legalities, in-scope items, any vulnerable components, and out-of-scope components before beginning an engagement.

Penetration Testing Methodology

Intelligence Gathering and Discovery

Once the legal and project-related formalities have been completed, the exploration phase begins with the sole aim of obtaining information. This information (e.g., network layouts, domains, servers, infrastructure details) helps to understand how the network works, including its assets (applications, systems, devices, anything with an IP).

Moreover, it is necessary to conduct proper reconnaissance and gather information about the systems. Using variously automated and manual tools, testers scan the system to find potential vulnerabilities or penetration points. These would be exploited by the testers in further steps. Tools such as Recon-Ng, Nmap, Spiderfoot, Metasploit, and Wireshark are usually used for this.

Scanning

This phase is performed to find vulnerabilities within the defined goals. It includes scanning the target for listening services/open ports, fingerprinting, and analyzing the running services to prepare a rough attack layout of the target systems.

It is worth mentioning that host scanning is the first step of a typical network Penetration Test. There the Pentesters scan the hosts to check whether there are any technical problems (firewalls, connection problems, etc.). Furthermore, the aim of the host scan is to agree on the test scope.

Exploitation

Once potential vulnerabilities are discovered, testers will use them in additional Penetration attempts to the system. This closely resembles how a cybercriminal would exploit these vulnerabilities and helps provide a better overall understanding. All steps, tools that are used, locations, and input methods for a specific issue are adequately documented to capture the entire process for later review. As a step in the Penetration Testing Process, these security issues are ranked based on how easy they are to exploit and the damage they can cause. This would support a huge oversight to the organization to prioritize fixes.

Specific assessments and goal-based scenarios are defined in “white box”, “black box” or “grey box” methodologies. The test cases are defined based on the amount of information available to the consultants before starting the evaluation.

Data Analysis and Reporting

After Penetration Testing is complete, detailed reports are prepared for corrective action. All identified vulnerabilities and recommended remedial methods are listed in these reports. You can customize the format of the vulnerability report (HTML, XML, MS Word or PDF) according to the needs of your organization.

Presentation of the Results

It is crucial that Penetration Testing results should be presented thoroughly, including an explanation of the vulnerabilities, further exploitation results, user rights management overview, and critics and results of the pre-agreed scenarios. Last but not least, recommendations to overcome and fix the vulnerabilities of the Pentesters.

At the end of the day, all questions of the customer should be answered, and a concrete list of measures should be defined for each vulnerability. Only then, a pentest will make sense.

After-Scan

For some projects, it might be wise to re-scan and re-check the findings to control the effectiveness of the implemented measures. Therefore, we always suggest the after-scan depending on the size of the project between 1 to 3 months. Pentester should be scheduling this time already in the final meeting, where the results are presented.

Wrapping-up

In this blog post, we explained what a standard Pentest Procedure looks like. We have gone through Pentest phases from the beginning till the end. Of course, there might be different executions of Pentests as there are various hardware/software available in the market.

Please keep in mind that a Penetration Test’s quality is heavily dependent on the Pentesters’ experience. Having said that, an experienced Pentester might try to exploit different vulnerabilities as per his/her experience.

If you want more general information about Pentesting, you can read our blog post here. If you want to start with your Penetration Tests, you can see how we can help you here.

About the Author

Penetration Testing Process

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

Penetration Testing Process Read More »

Pentests

Penetration Testing – All You Need to Know

In this blog post, we will cover all the details about penetration testing and how -when done properly- it can help your company.

What exactly is Penetration Testing?

Penetration testing, also called Pentest, is one of the most popular topics in today’s information security world. It is a security testing process applied to detect security vulnerabilities in computer systems, networks, and web applications.

These security tests are performed by “authorized” people (so-called ethical hackers) in order to detect logic errors and vulnerabilities in the specified information systems and to prevent the exploitation of these security vulnerabilities by malevolent people. Thus, suggesting measures to increase security levels of the tested environments. The main purpose of a Pentest is exploiting the related vulnerability and trying to obtain unauthorized access in a way without harming the system, rather than detecting vulnerabilities only.

A typical pentest process consists of stages listed below:

  • Customer meeting (gathering information and talking about test conditions)
  • Kick-off (scanning the test scope)
  • Vulnerability scan (scanning the networks provided by the customer)
  • Manual exploitations (detecting false positives, attempting to gain unauthorized access)
  • Scenario execution (pre-defined scenarios with or without prior knowledge about systems)
  • Pentest report (including detected vulnerabilities and measures against those)
  • Final meeting (presenting test report and suggestions)

Why do companies need Penetration Testing?

Pentest is one of the first steps of proactive security and helps you and your organization stay ahead of hackers. In a Pentest, a team of ethical hackers finds security vulnerabilities in your application, network, or system. Thus, helping you fix them before attackers take advantage of these issues and exploit them. There is no definition of a 100% secured system and there is no limit to the techniques that attackers will use to exploit the system. Possibilities of techniques vary around malicious people according to their experience with operating systems, software development skills, and information systems. Besides, it is always a decent choice to check the security vulnerabilities in your information systems by a third party.

Another important issue to mention here is that a pentest is not merely a vulnerability scan.  We will talk about this in detail later, but we experience a lot of companies using only vulnerability scanning tools and claiming that they have performed pentests themselves. However, that is far away from reality.

How can Penetration Testing help your organization?

Needless to say, pentests provide various advantages and promising improvement potential for the tested environment. The most common advantages for your organization can be summarized as;

  • Exploit vulnerabilities

Penetration testing explores existing weaknesses in your system or network infrastructure. A report informs you of your security vulnerabilities so you know what software and hardware improvements you must consider.

  • Display real risks

Penetration testers try to exploit identified vulnerabilities. That allows companies to see what an attacker could do in the ‘real world’. They might access sensitive data and execute operating system commands.

  • Ensure business continuity

To make sure your business operations are up-and-running all the time, in which you need network availability, as well as 24/7 communications. Each disruption will have a negative impact on your business. Penetration tests reveal potential threats and help to ensure that your operations do not suffer from unexpected downtime or a loss of accessibility.

  • Follow regulations and comply with certification requirements

Your industry and legal compliance requirements may decree a certain level of penetration testing. Think about the ISO 27001 standard, TISAX®, or PCI regulations, which requires all managers and system owners to conduct regular penetration tests and security reviews, with skilled testers.

  • Reduce cyber-security insurance premiums

Most Insurers will reduce the cyber-security insurance premium once you provide proof of a penetration test. Think about it, it is cheaper for them to ensure a secured network than an unknown one.

Types of Penetration Testing

There are various types of penetration testing available. Before selecting a suitable provider and methodology, it is always a good start to be familiar with the types of Pentest available, as engagements vary in focus, depth, and duration. Common ethical hacking methods include:

  • Internal/External Infrastructure Penetration Testing

An assessment of on-premise and cloud network infrastructure, such as virtual system hosts, routers, and switches. Also, Pentest can be framed as either an internal penetration test, focusing on assets inside the corporate network, or an external penetration test, targeting also corporate networks infrastructure which can be reachable from the internet. To scope a test, you will need to know the number of internal and external IPs to be tested as well as network subnet size.

  • Wireless Penetration Testing

A Pentest that specifically targets an organization’s WLAN (wireless local area network), including wireless protocols and Bluetooth. Additionally, it helps to identify access points, weaknesses in encryption and WPA vulnerabilities. To be able to conduct Pentest, testers need to know the number of wireless and guest networks, locations and SSIDs to be assessed.

  • Web Application Testing

A comprehensive assessment of websites and custom applications specifically delivered over the web, checking the uncover coding and development flaws that could be maliciously exploited. Before approaching a web pentest, it’s vital to clarify the number of apps that need testing, also including the number of static pages, dynamic pages and input fields to be assessed.

  • Mobile Application Testing

Applying mobile applications pentest on operating systems, which are IOS and Android, to identify authentication, authorization, data leakage, and session handling exploits. To scope a pentest, testers need to know the operating system types as well as versions. Moreover, testers can utilize an app to be tested on, the number of API calls, and requirements for jailbreaking.

TISAX®, ISO 27001 and Pentests

As you might know, there are various international and industry-specific standards for information security. ISO 27001 is the international standard for information security. On the other hand, TISAX® is the standard for the automotive industry when it comes to information security.

Why are we telling this? Because both standards require a safe and secure infrastructure for information security. Regardless of the clients’ industry, the client needs to have valid proof that regular vulnerability scans are being made. The results are being checked and respective security measures are taken. Having said that, soon we will cover the differences between penetration testing and vulnerability scanning.

In addition to that, quality management standards like IATF (QM for the automobile industry) also require pentesting results as proof of security from audited companies.

Long story short, the bigger the company, the more detailed pentests needs to be executed as per the information security standards. Thus, penetration tests are better provided via 3rd party professional service providers. Hence, ethical hackers.

What is the difference between Penetration Testing and Vulnerability Scanning?

Penetration testing and vulnerability scanning may be considered identical for many people. On the other hand, they are like two sides of one coin. They are quite different, on the other hand they bond with each other. Vulnerability scans look for known vulnerabilities in your systems and report potential exposures. Penetration tests are intended to exploit weaknesses in the architecture of your IT network and determine the degree to which a malicious attacker can gain unauthorized access to your assets. 

After the vulnerability scan, we may use results as an indicator to focus on a deeper perspective and exploitation of penetration testing. That is why we use them in combination.

Outcome

The evaluated results of a Pentest are vital assets for assessing the current security level of your IT systems. These results can also provide your company’s responsible managers with insightful information about identified security gaps, their actualities, and their potential impacts on the system’s functionality and performance. A seasoned penetration tester also presents Pentest results with a list of recommendations for their remediations as well as guide customers to develop a reliable security system, according to OWASP and CVSS,  and to prioritize their future cybersecurity investments. Even though a Pentest may involve the usage of automated tools, the focus is mostly still on the manual skills, professional knowledge, and experience of penetration testers.

After the Pentest, which path should I follow?

As important as having a Pentest, it is much more important to evaluate the results and act. Unfortunately, the most common mistake is to have a Pentest done quickly, examine the report, and close very urgent vulnerabilities only. It is a common situation that medium-level vulnerabilities are not closed after the Pentest and the same vulnerabilities appear again in the next Pentest run. In order to have a high added value for the work carried out, it is recommended to apply at least the following items:

  • Presenting the results to the management within the scope of a risk map, instead of just naming vulnerabilities (if this vulnerability is exploited by hackers, that will be the impact, etc.)
  • Examining the report in detail and determining who is responsible for each finding.
  • Meeting with system administrators and software developers and sharing the results.
  • Follow-up of the closing of findings.
  • Determining the next Pentest time

Wrapping-up

Security attacks may compromise your infrastructure as well as sensitive data, which might lead to critical damage to the company’s reputation and affect the business financially, operationally, and legally. Therefore, Pentest can definitely assist you to avoid costly security breaches. Likewise, combining Pentest with Vulnerability Scanning always would be a convenient idea to have more meaningful insights on vulnerabilities and potential breach points in your IT infrastructure.

Overall, from a security perspective, only Pentest can make a realistic assessment of your company’s “health” and its resistance to cyber-attacks. Also, Pentest can declare the strength of your company’s IT infrastructure whether successful or unsuccessful on a malicious attack. Most importantly, it can help you prioritize your security investments, comply with industry regulations, and develop underlying and comprehensive defensive mechanisms so that your business will be protected from future intruders in the long run.

About the Author

Penetration Testing Process

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

Penetration Testing – All You Need to Know Read More »

GAP Analyse für TISAX

How to Execute GAP-Analysis: VDA ISA Catalogue

You might be hearing the term GAP-Analysis and wondering which role it plays for TISAX®. Alternatively, you know very well what GAP-Analysis is but are not sure how you can use it for your TISAX® project. In both cases, you are more than welcome to enjoy our new blog post about GAP-Analysis: VDA ISA Catalogue.

What is a GAP-Analysis: TISAX® Fragenkatalog*? – Why is it important?

Great questions. Let’s start with the definition of a GAP-Analysis. It is a frequently used methodology, mostly by consultants. The goal of the GAP-Analysis is to find the GAP between the should situation and the as-is situation. Only then, the project plan can be outlined and the necessary corrective actions can be planned.

*Fragenkatalog is a German word for Questionerre. I wanted to use the German word in this blog post, as its commonly used in the industry.

If you don’t know where you are, it will be difficult to define the actions, and measures that you need to take for reaching your goals. The same applies to reaching your TISAX® Label. In VDA ISA Catalogue, there are controls divided into different sections as follows; Information Security Policies and Organization, HR, Physical Security and Business Continuity, Identity and Access Management, IT Security/Cyber Security, Supplier Relationships, and, Compliance.

Each of those controls should be graded regarding respecting maturity level. Maturity levels for TISAX® can be between 0 and 5. A 0 Maturity level is “Incomplete”, whereas a 6 Maturity level is Optimizing. Needless to say, incomplete is where almost no measures are taken. On the other hand, optimizing is where the processes are described, and executed and respective documentation is held accordingly. If you want to learn about the maturity levels of TISAX®, you can read our blog post here.

Once you define your maturity levels for each of the TISAX® controls, you can now define the corrective actions and measures. This gives you a clear understanding of how much resources must be put into the project.

What are the benefits of GAP-Analysis?

A thoroughly executed GAP-Analysis provides you with a clear understanding of where your TISAX® project stands. Thus preventing you to estimate arbitrary resources for your TISAX® project. On the other hand, it helps you to reflect on your company’s strengths and weaknesses regarding different TISAX® sections (mentioned above). For instance, your physical security measures can be well implemented. In addition to that, your HR processes can be in place and running seamlessly. However, a GAP-Analysis helps you to realize your IT-Security Processes are not mature enough, thus you might consider improving.

In order to get your TISAX® Label, as a rule of thumb, you need to have at least maturity level 3. Having said that, there are exclusions for this rule. Nevertheless, the maturity level is a good indicator of the remaining efforts of your company until the audit.

Think about the benefits mentioned above, even if you decide not to proceed further with your TISAX® project, you can have a great understanding of your organization’s Information and Physical Security status. You can always improve your processes accordingly.

How the outcome of the GAP-Analysis: VDA ISA Catalogue look like?

To start the GAP analysis, you need to go through each control listed in the VDA ISA catalogue. Please keep in mind that, there are must and should requirements, as well as specific requirements for Info High and Info Very High. Therefore, the prerequisite to start your GAP-Analysis is to make sure of;

  • Your scope and locations
  • Your TISAX® Assessment Level (AL2 or AL3)
  • Does your client require Info High or Info Very High?
  • Are any extra modules such as Data Protection or Prototype Protection needed?

It will be wise to agree with your client beforehand, on what is expected from you. Only then, you can get solid GAP-Analysis results. If you don’t know about the client’s requirements, you still can do the self-assessment to have a rough idea. More about TISAX® Self-Assessment is in this blog post.

Once you go through the controls and fill in respective maturity levels, you are ready to receive the first results. In the huge excel file – VDA ISA Catalogue, you can also see the graphical representation of the analysis.

Penetration Testing Process
Source: VDA ISA Fragenkatalog

What should I do with the outcome? – Interpreting results

Before we dive into interpreting results, I wanted to emphasize that there are no good or bad results. Results are there to show you and your organization where you currently stand. What very important is, however, having a look at the results objectively. As you want to reach your goal: TISAX® Label, now is the time to plan.

Let’s assume that your company doesn’t have a Change Process and documentation in place. Thus, you have graded yourself with a maturity level of 1. As we know from TISAX® guidelines, we need to aim at least for a maturity level 3. Therefore, let’s have a look at maturity level 3: Established

A standard process integrated into the overall system is followed. Dependencies on other processes are documented and suitable interfaces are created. Evidence exists that the process has been used sustainably and actively over an extended period.

Source: ENX TISAX® Participant Handbook

So, what do you need to do now? Easy. First, you need to make sure that you defined a change process, and integrate it into your systems. Secondly, make sure that not only the process itself but also the process instances are documented. Last but not least, you need to have proof that you have applied the change process and executed it with proper documentation. For instance, you can make a change request, let’s say, a new software rollout, review the software, add it to your software list (IT Assets), and release the approved software. All documented. Voilá!

How VDA ISA Catalog is used to determine the maturity level?

As mentioned above, 6 different maturity levels are defined in the TISAX® participant handbook. While performing the GAP-Analysis you need to evaluate your companies, processes, policies, and documentation. Thus, deciding your maturity level accordingly. If you are not sure, grading one lower level will always give you a safety margin. It is wise not to estimate higher maturity levels, which can hinder you from taking necessary measures.

At the end of the day, the auditor will assess the controls objectively. If a control is not fully applied, or any critical prerequisites are missing, then this will result in a low maturity level. In fact, a 0 or a 1 maturity level for TISAX® is not acceptable. Thus, you have to make sure not only you need to get a maturity level of 3 on average, but also avoid maturity levels 0 and 1.

How can external help accelerate my success with VDA ISA Catalogue?

There are multiple options for how external (professional) help can accelerate your success with the GAP Analysis: VDA ISA Catalogue. First, the results and the precision of the average maturity level will be reliable. Secondly, an external consultant will provide an objective perspective to the analysis. In return, you will avoid overestimating your maturity level, therefore increasing your chances of failure. As well as, underestimating your maturity level, therefore assigning too many resources to the project.

In both cases, having a professional while executing your GAP Analysis will help significantly. In addition to that, your outcome will be better off, when you define the measures to be taken. Thus, your resource allocation will be respectively precise, not arbitrary,

How costly is the GAP-Analysis?

The costs of GAP-Analysis depend on your company size and your team. If you want to run the GAP-Analysis on your own, you need to consider the time spend trying to understand the VDA ISA Catalogue. On top of that, you need to make sure that you also understand the controls and their implications. Thus, you can roughly estimate 2 to 4 days, with 2 employees executing the Analysis.

Book a Workshop with us and Save Time&Money

Not to brag, but we run a TISAX® Workshop, where we help you with your GAP-Analysis. At the end of the workshop, you will not only receive the results but also your Roadmap for TISAX®, a comprehensive project plan, customized for your company. Here you can find the details of our Workshop for TISAX®.

External help will also decrease the time spent on the GAP-Analysis. A one-day workshop with preparation and a final report starting from 3.000€ can be estimated.

Wrapping-up

Whether you want to execute the GAP-Analysis on yourself, or you want to get external help onboard, the benefits of GAP-Analysis: VDA ISA Catalogue is enormous. At the same time, crucial for the success of your TISAX® project!

TISAX® ist eine eingetragene Marke der ENX Association. Die 360 Digitale Transformation steht in keiner geschäftlichen Beziehung zur ENX. Mit der Nennung der Marke TISAX® ist keine Aussage des Markeninhabers zur Geeignetheit der hier beworbenen Leistungen verbunden. TISAX® Assessments, zur Erlangung von Labels, werden nur von den auf der Homepage der ENX genannten Prüfdienstleistern durchgeführt.

About the Author

Penetration Testing Process

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

How to Execute GAP-Analysis: VDA ISA Catalogue Read More »

TISAX und ISO 27001

TISAX® and ISO 27001: Differences and Similarities

In this blog post, we want to compare TISAX® with ISO27001, dive deep into both standards and summarize the results for you. We won’t only talk about differences, but also mention similarities and synergies between the two standards. Here is a comprehensive comparison between TISAX® and ISO 27001.

What are the main differences between TISAX® and ISO 27001?

Although TISAX® originally was derived from ISO 27001, the two standards are completely independent of each other. There are also no dependencies regarding the application, requirements, audits, and certifications. In other words, if you have TISAX® or ISO 27001, one doesn’t replace another.

Having that in mind, we have compiled a list of differences as a summary. However, in the further part of this post, we will go into details of each item:

  • ISO 27001 is a certification, while TISAX® is a label.
  • ISO 27001 is international, but TISAX® is not yet international.
  • TISAX® is used in the Automotive Industry, whereas ISO 27001 can be applied to all industries.
  • In TISAX®, the whole company is being assessed. In ISO 27001 functions, production lines can be assessed individually.
  • TISAX® Catalogue requires the maturity levels of each and every control, ISO 27001 doesn’t measure the maturity levels.
  • Re-auditing structure is different. TISAX® Re-Audit is after 3 years, ISO 27001 on the other hand has it on a yearly basis.
  • As TISAX® is automotive-specific, it includes details like Prototype Protection, Data Protection (which is way stricter than ISO 27001 especially when Assessment Level 3 is desired)
  • TISAX® has 9 months from the beginning to implement all the major and minor discrepancies.
  • TISAX® has a limited choice for Auditors in comparison to ISO 27001.
  • In order to simplify the differences, we have divided them into 2 groups; structural and technical differences.

In order to simplify the differences, we have divided them into 2 groups; structural and technical differences.

Structural Differences

Structural differences are the differences regarding the process, context, and definition of the audits. As mentioned above, ISO 27001 is a certification for Information Security. However, TISAX® is given as a label. Companies that have TISAX® are listed in the ENX Portal. This is to serve the purpose ofTISAX®. If you want to learn more about this, here is a suggested Blog Post.

Furthermore, ISO, hence the name, is an international standard. On the other hand, TISAX® is a requirement from VDA, which is mainly German. Nevertheless, we believe that TISAX® is growing to be the European Information Security Standard for the Automotive Industry. Let’s wait and see. Moving on, TISAX® is an industry-specific label, whereas ISO 27001 can be applied to all industries. In addition to that, ISO 27001 can be applied to a production unit or department. For TISAX however, the whole company -with the option to choose locations- needs to be audited.

Finally, the re-auditing structure is different. ISO 27001 requires a yearly audit, whereas TISAX® re-certification is after 3 years.

Technical Differences

ISO 27001 has 114 controls, which are used as the basis of the assessment. However, those controls don’t have a maturity level measured. In TISAX® maturity levels are defined and used as criteria for the achievement of the label. There are 6 maturity levels in TISAX®, from 0 to 5. An average of 3 is required to have the label. On the other hand, for some controls, maturity levels need to be a minimum of 2. Therefore, TISAX® is way more concrete when it comes to implementation as it has to measure the maturity levels.

As TISAX® is an automotive industry standard, it includes Prototype protection. The data protection section of the TISAX® is way more comprehensive and restricted than ISO 27001, especially for Assessment Level 3.

One more technical difference is that, from the day of the first audit, TISAX® has 9 months deadline for implementing the measures defined in the audit. If those measures are not implemented within the 9 months, the application phase for the Label has to restart. Below is the TISAX® project timeline.

Tisax Consultancy Services

When it comes to choosing the Auditing company,TISAX® has a way-limited set of options in comparison with ISO When it comes to choosing the Auditing company, TISAX® has a way-limited set of options in comparison with ISO 27001. As of January 2023, TISAX® has only 14 Auditing bodies worldwide. Having said that, we are done with the differences. Let’s focus on the similarities between TISAX® and ISO 27001 💃

Similarities Between TISAX® and ISO 27001

First of all, TISAX® is derived from ISO 27001. The control catalog of TISAX® is rooted in Annex A of ISO 27001. Therefore, we can easily say that the main idea and aim are pretty similar. Secondly, regardless of which audit the company successfully passes, the information security levels will be almost identical. In this sense, both labels are there to make sure a high information security standard is set.

If you are familiar with the ISO PDCA (Plan, Do, Check, Act) circle, TISAX® also requires a Continuous Improvement Process, where the aims are almost similar. We believe that a Continuous Improvement Process is crucial not only for information security but also for the other processes of the company.

Do TISAX® and ISO 27001 replace each other?

No. Definitely not. TISAX® and ISO 27001 are not mutually exclusive. Therefore, depending on your company’s needs, industry, and goals you can choose between two labels. Can’t you have both at the same time? Yes, you can. More on this is below.

Let’s assume that your company is working exclusively with the automotive industry. Then the TISAX® label might make more sense. If, however, you want to have a certification that’s known worldwide, then ISO 27001 can be a better option.

Does it make sense to have two certificates at the same time?

The answer is, it depends 🙂 Yes, I know it’s not a proper answer. But if you are exclusively delivering services or producing goods for the automotive industry, then TISAX® alone might serve your purposes. Having both will not hurt, as having one before the other will ease the total pain of audits. In this case, we suggest having the TISAX® label before ISO27001.

Wrapping-up

ISO 27001 has 114 controls, and TISAX® for information security has approx. 70. Therefore, one can easily claim that both standards are quite similar. Moreover, those controls from TISAX® are derived from ISO 27001. Depending on your company’s needs, goals, and industry you can choose between two labels. In the best case, you can have both.

You’re not sure where to start or which one to choose? We are here to help you. You can get in touch with us here.

TISAX® ist eine eingetragene Marke der ENX Association. Die 360 Digitale Transformation steht in keiner geschäftlichen Beziehung zur ENX. Mit der Nennung der Marke TISAX® ist keine Aussage des Markeninhabers zur Geeignetheit der hier beworbenen Leistungen verbunden. TISAX® Assessments, zur Erlangung von Labels, werden nur von den auf der Homepage der ENX genannten Prüfdienstleistern durchgeführt.

About the Author

Penetration Testing Process

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

TISAX® and ISO 27001: Differences and Similarities Read More »

Digital Transformation

How TISAX® Certification can boost your Digital Transformation?

First of all, to answer this question, we need to understand the role of TISAX® Certification in Digital Transformation. Therefore, we need to explain what TISAX® is. Some of you might already know what TISAX® is and who needs TISAX® Certification. Therefore, they can jump to the second section directly.

TISAX® Certification is more than Information and IT-Security. In this post, we will explain how TISAX® Certification can boost your Digital Transformation.

What is TISAX® Certification?

Let’s start with the acronym. TISAX® stands for Trusted Information Security Assessment Exchange. Or so-called; ISO 27001 for automotive. However, TISAX® is way more specific and in our opinion useful than any other Information and IT Security certification. In 2017, the German Association of the Automotive Industry (Verband der Automobilindustrie, VDA) published its list of criteria regarding information security in the automotive industry.

Therefore giant automotive producers like VW, BMW, Daimler are demanding their suppliers to be TISAX® certified. Regardless of whether you are an OEM producer or a creative agency that designs websites, you will need the certification. Of course in case you want to work with those companies. This means even a small company with 5 employees might be required to have TISAX® Certification. Hence the size of the company doesn’t play a role in the TISAX® requirement.

You can find detailed information in this blog post about TISAX Certification.

What is the role of TISAX® Certification in Digital Transformation?

TISAX® Certification requires companies to have processes in place for IT and Information Security. Furthermore, processes have to be monitored in HR, Controlling (Compliance), and Procurement departments as well. Those processes include Change Management, Patch Management, Incident Management, Supplier Evaluation, Document Classification, GDPR Processes, etc. All of those processes are the foundation stones of the TISAX® Certification. Therefore, TISAX® helps companies by laying the basics of business process management (BPM).

Up to this point, it might sound obvious. However, in reality, these companies are working in complex processes, and unintegrated systems and they lack a center of management. Therefore, if a company’s processes are not in place, TISAX® can really benefit by putting things in order.

On top of that, TISAX® requires documenting and monitoring those processes with pre-defined KPIs. In turn, which helps companies to be more transparent, monitorable, and secure. Those KPIs are the starting points for Continuous Improvement Processes. There are also companies that take a couple of steps further by using the accumulated data for further analysis and future projections.

One major thing that TISAX® Certification helps companies with is Information Security Management Systems (ISMS). TISAX® requires a structured ISMS, having the roles (and process owners) defined. In addition to that, necessary policies, procedures, and registers are defined and put in place.

Finally, TISAX® Certification also helps with Risk Assessment for both IT and Non-IT Assets. That in turn, helps the Business Continuity Management. Often those topics are underestimated in businesses.

How TISAX® can help further with Digital Transformation?

While implementing TISAX® processes, you can also consider a further process implementation phase. As mentioned above, KPIs from TISAX® can help with Continuous Improvement Processes. Every process can be improved. However, the process needs to be documented first, before any attempt of improvement.

In a nutshell, process optimization follows the steps below:

  • Define
  • Optimize
  • Digitalize
  • Automate
Penetration Testing Process
Process Optimization Steps

Furthermore, there are more brick stones that TISAX® Certification lays for your company:

  • Creating employee awareness for Information and IT Security
  • Regular training for a smooth operation
  • Processes running instead of fulfilled documentation for the sake of certification
  • Tracked KPIs for Information IT-Security Performance

Want to learn about your TISAX® readiness level?

A good way to assess yourself for TISAX®, as well as your processes in place, is to run a Self-Assessment for TISAX®. You can do it in several ways, here is our blog post about the benefits of Self-Assessment for TISAX®.

By running the Self-Assessment for TISAX® you can assess your TISAX® maturity level. On top of that, the result will also be a good indicator of how your company is digitally advanced. Having said that, a digital maturity level is a key indicator for Digital Transformation. Thus, we strongly recommend having an eye on Digital Maturity Level as a KPI.

What’s next?

There are 2 options worth mentioning here. Firstly, if you are in the process of getting your TISAX® Certification, you might consider the implementation from a long-term perspective. How this certification will help my Digital Transformation goals? You might also benefit from getting external help.

Secondly, if you already have your TISAX® Certification in place, but are not sure how to integrate it into your Digital Transformation, here are a couple of options on how we might help you.

Wrapping-up

In this blog post, we have tried to give you a quick overview of TISAX®. As well as, how a TISAX® Certification can help you with your Digital Transformation.

Finally, as of September 2021, TISAX® is well known in Germany, but not necessarily often used in any other country. My prediction is TISAX® will become a global standard by 2030. As it slowly gains traction from countries like the US, UK, Portugal, Poland, Czech Republic, and Turkey.

TISAX® ist eine eingetragene Marke der ENX Association. Die 360 Digitale Transformation steht in keiner geschäftlichen Beziehung zur ENX. Mit der Nennung der Marke TISAX® ist keine Aussage des Markeninhabers zur Geeignetheit der hier beworbenen Leistungen verbunden. TISAX® Assessments, zur Erlangung von Labels, werden nur von den auf der Homepage der ENX genannten Prüfdienstleistern durchgeführt.

About the Author

Penetration Testing Process

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

How TISAX® Certification can boost your Digital Transformation? Read More »

Self Assessment TISAX

How to perform a Self-Assessment for TISAX®?

Your company has now decided to get a TISAX® Certification. Maybe you are required to be TISAX® certificated. In both cases, welcome to the club! TISAX® is an extremely deep topic, therefore if you are new to TISAX®, I would definitely recommend starting with this Blog Post.

In this post, after covering some basics, we will focus on performing a Self-Assessment for TISAX. Hence, this blog post aims at companies, which are more advanced in their TISAX Certification processes. For instance, companies that already decided to proceed with the TISAX Certification.

What does a typical Roadmap for TISAX® look like?

This is a very often asked question, therefore we want to start with the Roadmap for TISAX®. After deciding to get your TISAX® Certification, you should start with registration to ENX TISAX® Portal.

The registration fee is about 400€ (as of August 2021). After the registration, you will receive your SCOPE ID. Thus, our congrats, you have successfully completed the first step towards your TISAX® Certification. 👏

Penetration Testing Process
TISAX® Certification Stages

After this step, you need to choose the Auditing company, hence the Auditor. However, we strongly suggest completing your preparation before deciding on your audit date. Why is that? If you are not sure about how fit you are for your audit, then you are doing two things. Firstly, you are putting time pressure on your shoulders. Secondly, you are risking a smooth audit by skipping the preparation. Therefore, preparation first!

You can choose your auditor from the given list of companies. Examples of those companies are; DEKRA, TÜV, KPMG, etc. You can get offers from different auditors. Then decide which one suits you best. After your decision, the auditor company will ask you to define an Audit Date and a Kick-off meeting. We suggest having enough time between the audit and the kick-off meeting.

How do you prepare for your TISAX® Certification?

You need to prepare your homework, before choosing the audit date. The preparation time depends on your company’s ISMS readiness level. We suggest taking enough time for preparation. Hence, avoid rushing into the audit. Let’s dive into the preparation steps.

A GAP Analysis is like an X-Ray for doctors. It defines the maturity level of your company. It also shows in which areas your company needs to improve to get the TISAX® Certification. Here is what a GAP Analysis looks like:

  • Physical Security Questionnaire
  • ISMS Structure
  • Technical Security
  • Self-Assessment

This blog post will give you detailed information about Self-Assessment for TISAX®. Therefore we will only cover this aspect of the GAP Analysis. The result of the GAP Analysis will be affected by your ISMS structure, document management system, documentation policies, security policies, network plan, etc.

TISAX® requires a certain structure and clearly defined policies. Therefore it’s crucial to have them in place. If that’s not possible yet, performing a Self-Assessment for TISAX® helps you to see in which areas your company needs more preparation. As well as which requirements are a must-have.

What are the components of Self-Assessment for TISAX®?

TISAX® Self-Assessment is a catalog from VDA (Verband der Automobilindustrie – German Association of Automotive Industry). The catalog contains questions about Information Security, Prototype Protection, and Data Protection. However, please keep in mind that not all three sections are valid for all TISAX® Certification levels.

The self-assessment will also be provided as audit documentation. Therefore, it’s crucial to execute thoroughly. We suggest taking it twice, before the project kick-off, and then building from there. Hence the final version of the self-assessment can be provided without any additional effort.

Cover Page

Firstly, you need to start with the cover page. Here you provide basic information about your company. For instance your Scope-ID* and DUNS number**.

* You receive your SCOPE-ID, once you have registered in the ENX Platform.

**You receive your DUNS number via this link.

Maturity Level and Definitions

After that, we can start explaining how to proceed with sections. Each section has different questions. You need to answer those questions as per your company’s maturity level. Therefore, you need to know what’s meant by maturity level.

The maturity level is explained in the maturity levels of the catalog. There are six maturity levels according to VDA from 0 to 5:

  • Incomplete
  • Performed
  • Managed
  • Established
  • Predictable
  • Optimizing

It’s also wise to read the definitions before moving on to answering the questions. Thus you can have a profound understanding of the logic of the VDA Catalogue.

Information Security

In each section, there are multiple questions to determine your maturity level. There are different categories under the Information Security section. As a result of your assessment, you will be graded under the categories:

  • Information Security Policies and Organisation
  • Human Resources
  • Physical Security and Business Continuity
  • Identity and Access Management
  • IT Security/Cyber Security
  • Supplier Relationships
  • Compliance
  • Prototype Protection (comes from the Prototype Protection section)

How do I define my maturity level during Self-Assessment for TISAX®?

Firstly, to define your maturity levels, you need to pay attention to the must and should requirements of the control questions. In case you want to improve your maturity level, those requirements need to be in place. Needless to say, your maturity levels depend on to what extent you have these requirements fulfilled.

As there are many control questions with multiple requirements each, it’s wise to spare some time for the assessment. It is worth investing in understanding the criteria to have a smooth audit in the future. Therefore we strongly suggest performing the self-assessment at the beginning of the project.

Finally, you will need to fill in the reference documentation (column G). This column can be filled by providing the link to the reference documentation in your ISMS system. Alternatively, you can type in the name of the documented file in the related control question. Here you can download the latest version of the VDA Catalogue which was released on April 21st, 2021.

What are the success criteria of Self-Assessment for TISAX®?

Firstly, the average of all maturity levels should be a minimum of 3. However, that alone doesn’t guarantee your certificate. Secondly, you shouldn’t have any 0 or 1 grades. Thus, having Incomplete or Performed as a maturity level is a no-go for TISAX®.

Therefore it’s crucial to run a Self-Assessment for TISAX® before you define your audit date. You will not only see where are your improvement potential. You can also have a backup plan to make sure that you are ready for your audit.

Finally, Self-Assessment for TISAX® provides a good benchmark in case your company prioritizes one of the categories mentioned above. Needless to say, you can always improve.

What are the costs of TISAX® Label?

Here is a cost breakdown that you can use:

  • ENX Registration approximately 405€ (as of August 2023)
  • ISMS (Information Security Management System) depending on the tool in use
  • Auditor Fees start from 5.000€ (depending on the Auditing Company)
  • Consultancy for TISAX® (getting an expert team on board for a smooth audit) starting from approx. 20.000€

The prices given above are approximations of what we have experienced in the market. Each cost can vary depending on the number of locations, existing infrastructure, and your TISAX® maturity level (i.e. the result of your TISAX® Self-Assessment).

Wrapping Up

Preparing for your TISAX® Audit is a tedious, time-consuming process. It also needs hard work. However, the benefits of the TISAX® certification outweigh the efforts. Therefore, getting an expert on board even from the beginning is wise. Alternatively, you can book a workshop with us to define your Roadmap for TISAX®. Do you have any other questions? Please contact us!

TISAX® ist eine eingetragene Marke der ENX Association. Die 360 Digitale Transformation steht in keiner geschäftlichen Beziehung zur ENX. Mit der Nennung der Marke TISAX® ist keine Aussage des Markeninhabers zur Geeignetheit der hier beworbenen Leistungen verbunden. TISAX® Assessments, zur Erlangung von Labels, werden nur von den auf der Homepage der ENX genannten Prüfdienstleistern durchgeführt.

JOIN OUR NEWSLETTER

Thus you will be notified when we have new blog posts. We won’t spam you, promise!

Penetration Testing Process

Can Adiguzel is the founder of 360 Digital Transformation. He is in IT-Project Management more than 11 years. He is passionate about Information Security for Mittelstand and helps Mittelstand to overcome their Information Security challenges using a hands-on consulting approach.

About the Author

Penetration Testing Process

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

How to perform a Self-Assessment for TISAX®? Read More »

TISAX Blog

TISAX® Label: All you need to know

What’s TISAX?

Let’s start with the acronym. TISAX® stands for Trusted Information Security Assessment Exchange. Or as called in the industry ISO 27001 for automotive. In 2017, the German Association of the Automotive Industry (Verband der Automobilindustrie, VDA) published its list of criteria regarding information security in the automotive industry.

Which parties are included?

Before the TISAX® certification members of VDA ran their internal assessments and also assessments for their suppliers, partners, and service providers. However, this individual assessment per provider required partners to spend time & money on assessment for each of their clients. Let’s assume that you are a producer from Bayern and you have to pass through AT LEAST 3 different assessments if you provide goods for Daimler, BMW, and VW.

To reduce duplicate efforts for similar assessments for different companies, VDA came up with its list of criteria; TISAX®. Which has a catalog of criteria, audits, processes, and KPIs, therefore, as a result, TISAX® Certification. If a supplier is TISAX® certified, it assures the controlled sharing and security of the data being held.

VDA has chosen a neutral third party, the ENX Association, which accredits auditors, maintains the assessment requirements, monitors the audit quality, and finally keeps audit results. Therefore, in addition to ENX, there are neutral auditing firms such as TÜV, Dekra, PWC, KPMG, Bureau Veritas, Deloitte, etc.

Who needs to be TISAX® certified?

If you are a supplier, service provider, or partner to a VDA member (i.e VW, Daimler, AUDI, BMW, Porsche, Continental, MAGNA, Škoda, etc.), a TISAX® Certification will make sure that you are eligible to continue proving your services, and/or take part in tenders. As more and more companies are getting TISAX® certification, companies without the certification will have difficulties being a part of the supply chain for big automotive producers. That applies to Tier 2 and Tier 3 suppliers as well as other service providers.

What are the major benefits of TISAX®?

First and foremost, TISAX® is there to create a base information security level within the automotive industry. And if we think about patents, prototypes, and R&D efforts, and how many different stakeholders are included; information security is crucial for a smooth and secure supply chain.

Let’s continue with the supply chain, every producer would want to make sure that their supply chains are secure and built with strong links, which means reliable suppliers. TISAX® certifications can provide a comparison ground, as well as a trust basis. This also ensures the suppliers are working towards improving their internal security measures and processes.

As mentioned above, by having a common assessment guideline, duplication efforts are eliminated. Therefore, both suppliers and producers can save significant time and money.

Which levels of certification do I Need?

There are 3 levels of assessment for TISAX® certification:

Level 1: At this level, suppliers should fulfill the Information Security Assessment (ISA) questionnaire and have a certain level of maturity to be approved by the TISAX® Auditor

Level 2: If the supplier wants Level 2 certification, a self-assessment questionnaire will be followed by remote compliance checks by the audit provider

Level 3: Suppliers who work with confidential data have to go through an on-site inspection by the audit provider

Which steps are included in TISAX® Label?

First of all, the company should register on the ENX platform. This is the first step of the TISAX® certification regardless of the certification level. Then the companies should decide which certification level they need and select the auditor. Please keep in mind that by selecting an audit provider, this company is automatically excluded from any TISAX® consultancy service throughout the certification.

Then ISA questionnaire should be completed by the company. Here is quite important to consider having expert help, to carefully identify the basis for the GAP analysis. Then the results are shared with the auditor. Depending on which level, the next steps might vary. However, the essence is that the auditor sends an audit report with the necessary precautions. Those precautions need to be fulfilled before getting the TISAX® Label.

Then the TISAX® Label must be renewed every 3 years. However, the procedure for recertification differs from that for initial certification. In the case of recertification, annual audits must be carried out to ensure that the processes are being executed and comply with the TISAX® requirements.

What are the costs of the TISAX® Label?

There are 4 possible cost items. The registration fee paid to ENX is mandatory and is about 500 € per site. Then a mandatory fee for the audit provider, which depends on your choice and varies between 5,000 and 10,000 € depending on the audit level. There are also operational costs that your employees should spend on preparing for the audit, which can also be significantly reduced with external help.

For pricing, we offer our Workshop for TISAX® for your personal GAP analysis. In addition, the consulting costs can be calculated between 16.000-25.000€.

For instance, we as 360 Digital Transformation help you from the beginning to the end of the certification process. Through GAP analysis, process optimization, framework creation and ISMS creation, tool selection, and support during the audit. We have helped more than 50 companies to achieve their TISAX® Label.

TISAX® ist eine eingetragene Marke der ENX Association. Die 360 Digitale Transformation steht in keiner geschäftlichen Beziehung zur ENX. Mit der Nennung der Marke TISAX® ist keine Aussage des Markeninhabers zur Geeignetheit der hier beworbenen Leistungen verbunden. TISAX® Assessments, zur Erlangung von Labels, werden nur von den auf der Homepage der ENX genannten Prüfdienstleistern durchgeführt.

What are the differences between TISAX® Label and ISO 27001?

TISAX® Label and ISO 27001 are quite similar, as both are standards for ISMS (Information Security Management Systems). The difference between TISAX® certification and ISO 27001 is that TISAX® Label is required by the automotive industry. So if you are a supplier or service provider to the automotive industry, then you may need TISAX® Label. On the other hand, ISO 27001 is a general standard, which means it can be applied in any industry. However, in this blog post, we will not go into detail about the application differences between the two standards.

For companies wishing to obtain both certificates, we recommend starting with TISAX® Label and then proceeding to ISO 27001.

If you want to learn more about the differences between TISAX® and ISO 27001, we recommend reading this blog post.

Two ways we can help you

We are here to help you get your TISAX® Label with less cost and faster. 

Would you like to learn more about TISAX® or do you have any questions?  Then schedule a free-of-charge meeting.

Do you already want to start with your TISAX project? Then book our GAP Analysis so that you have your maturity level and your Roadmap for TISAX® clearly defined.

About the Author

Penetration Testing Process

Can Adiguzel is the founder of 360 Digital Transformation. He is a TISAX® consultant and ISO 27001 Lead Auditor. He has been working in IT project management for more than 11 years. His passion is information security for SMEs and he helps SMEs overcome their information security challenges with a hands-on consulting approach.

TISAX® Label: All you need to know Read More »

360 Digitale Transformation
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.