What is VDA ISA?
The VDA Information Security Assessment (ISA) is the standardized audit catalog developed by the German Association of the Automotive Industry (Verband der Automobilindustrie). It serves as the basis for TISAX assessments and defines the specific criteria against which organizations are evaluated.
Structure
The VDA ISA catalog covers three main modules:
- Information Security: Based on ISO 27001 with automotive-specific additions
- Prototype Protection: Physical and digital protection of prototypes
- Data Protection: GDPR-aligned personal data protection requirements
Maturity Model
Each control area in the VDA ISA is assessed using a maturity model with levels from 0 to 5:
- 0: Incomplete
- 1: Performed
- 2: Managed
- 3: Established (target level for most controls)
- 4: Predictable
- 5: Optimizing
Updates
The VDA ISA catalog is regularly updated to reflect evolving threats and best practices. Organizations should ensure they are assessing against the current version when preparing for TISAX.
Back to Glossary