Valeo · security governance / June 2026

NIS2, ISO and TISAX should not become three separate evidence factories

Different frameworks often ask about the same underlying operation in different language. The goal was one evidence source for a shared control instead of three parallel collection processes.

2 min read
Valeo · security governance
NIS2ISO27001TISAXcontrols

Situation

Large organizations live with several compliance and audit frameworks at the same time. If every framework gets its own evidence process, multiple teams collect the same technical data repeatedly and often at different points in time. That is not only wasteful; it also creates a consistency risk between audit views.

Approach

I organized controls by the underlying operation rather than by framework name. Where two requirements pointed at the same access-control, patching or governance process, I looked for a shared source system and a shared way to produce evidence. Framework-specific differences stayed in the interpretation layer instead of being duplicated in data collection.

Outcome

Duplicate requests decreased and the same state became easier to present consistently across different audit perspectives. Technical teams needed less framework-specific vocabulary because the governance layer translated shared operations into the language expected by each framework.