Glossary Term

VDA ISA

VDA Information Security Assessment - the audit catalog used as the basis for TISAX assessments in the automotive industry.

What is VDA ISA?

The VDA Information Security Assessment (ISA) is the standardized audit catalog developed by the German Association of the Automotive Industry (Verband der Automobilindustrie). It serves as the basis for TISAX assessments and defines the specific criteria against which organizations are evaluated.

Structure

The VDA ISA catalog covers three main modules:

  • Information Security: Based on ISO 27001 with automotive-specific additions
  • Prototype Protection: Physical and digital protection of prototypes
  • Data Protection: GDPR-aligned personal data protection requirements

Maturity Model

Each control area in the VDA ISA is assessed using a maturity model with levels from 0 to 5:

  • 0: Incomplete
  • 1: Performed
  • 2: Managed
  • 3: Established (target level for most controls)
  • 4: Predictable
  • 5: Optimizing

Updates

The VDA ISA catalog is regularly updated to reflect evolving threats and best practices. Organizations should ensure they are assessing against the current version when preparing for TISAX.

Back to Glossary

Need Expert Guidance?

Our consultants can help you understand and implement the requirements of this standard or framework.