Clear scope and context
Management-system readiness
ISO 27001 and TISAX Operating Model
Build an information-security operating model that can run between audits instead of relying on a last-minute documentation exercise.
Trigger situations
Trigger situations
- Customer requirement
- Upcoming audit or assessment
- Certificate renewal
- Failed readiness review
- Evidence scramble
- Automotive or industrial customer expectations
Problems addressed
Problems addressed
- Scope does not match assurance needs
- Control ownership is unclear
- Evidence is hard to find
- Policies do not match operating reality
- Management review and remediation cadence is weak
Engagement outcomes
Engagement outcomes
Control ownership model
Evidence-management approach
Internal-audit readiness
Management-review cadence
Post-assessment improvement path
Assessment and advisory scope
- Initial readiness or maturity assessment
- Scope and context
- Governance
- Risk treatment
- Policy architecture
- Evidence management
- Internal audit readiness
- Management review
Implementation and delivery scope
- ISMS operating model
- TISAX readiness support
- Control ownership
- Evidence cadence
- Remediation tracking
- Operational governance routines
Typical deliverables
- Readiness assessment
- Scope and evidence map
- Control ownership matrix
- Roadmap
- Management review structure
- Internal-audit readiness plan
Engagement process
Engagement process
Clarify certification, TISAX or customer-assurance drivers.
Review scope, controls, risks, evidence and cadence.
Design the ownership and evidence model.
Support remediation and ongoing governance routines.
Follow-on work can include implementation support, internal-audit readiness, evidence remediation or ongoing ISMS/TISAX governance cadence.
Client responsibilities
Client responsibilities
- Provide scope context and asset/process information.
- Provide current policies and evidence.
- Nominate accountable control owners.
- Engage authorised assessment bodies where certification or labels are required.
GRCForce responsibilities
GRCForce responsibilities
- Design the operating model.
- Support implementation and evidence readiness.
- Prepare improvement roadmap and governance cadence.
- Keep readiness support separate from certification decisions.
Exclusions
Exclusions
- Certification issuance
- TISAX label issuance
- ENX assessment provider role
- Guaranteed certificate
- Guaranteed TISAX label
- Legal advice
Important boundaries
Important boundaries
- GRCForce does not issue ISO certifications.
- GRCForce does not issue TISAX labels.
- Certification and label decisions are made by authorised independent assessment bodies.
- Readiness support does not guarantee certification or label achievement.
Related thinking
Related thinking
Supporting capabilities
Supporting capabilities
Other flagship offers
Other flagship offers
NIS2 and DORA Readiness
Separate NIS2 and DORA workstreams, or connect both into one practical governance, control and evidence model where that is the right fit.
Fractional CISO and GRC Leadership
Controlled senior security and GRC direction for organisations that need leadership capacity without presenting it as unlimited access or a substitute for client accountability.