Is your ISMS inventory outdated before the auditor even opens it?
For ISO 27001 you maintain an asset register in Excel: a snapshot from last quarter, while the real network keeps moving. COD runs your management system on the same living asset data as your operations, with versioned risks and an evidence-grade audit log. On-premises, multi-tenant.
GRC risk matrix: impact × likelihood, color-coded by risk level.
Know the feeling?
The ISMS inventory is outdated before the auditor opens it
The pain: Your asset register lives in Excel, copied off the real network. Every new VM, every replaced switch, every OT device has to be added by hand. And in day-to-day business, that is exactly what gets done last.
The consequence: Systems missing from the inventory stay unassessed and unprotected, and in the audit the gap between register and reality surfaces as a finding.
How COD solves it: The GRC module works on the same living asset data as your operations: COD-Network automatically discovers every IP-addressable device from IT to OT. Risks are assessed per asset and versioned, with BSI 200-3 defaults and the live status of the specific asset. No more double maintenance.
Scraping together audit evidence, and none of it holds up
The pain: Before every audit the hunt begins: who changed which policy or risk assessment, when, and why? The answers are buried in emails, file names and colleagues' memories. And Word and Excel histories can be altered after the fact.
The consequence: Patchy or unreliable change histories end up as audit findings. And after an incident there is no evidence-grade proof of which state applied when.
How COD solves it: Every change to assets, controls, policies and risk assessments is logged: who, when, what, where, why. The audit log is append-only and protected by database triggers against retroactive editing and deletion, with field-level diff logging. Compliance data is kept separately in its own PostgreSQL database.
93 controls in Excel, three standards in three silos, and NIS2 piles on
The pain: You track the implementation status of the ISO 27001 Annex A controls by hand in Excel, with no link to policies or assets. Where ISO 9001 or ISO 22301 run in parallel, separate folder silos with overlapping content emerge, and NIS2 adds extra evidence pressure on top.
The consequence: Real progress is not reliably visible to you or to management. Every status request means manual consolidation, and contradictions between the silos are a constant source of errors.
How COD solves it: The GRC module brings ISO 27001 with all 93 Annex A controls, plus ISO 9001, ISO 22301 and the BSI 200-3 methodology onto one common data foundation. NIS2 readiness becomes demonstrable on it as well. Per control you maintain applicability, implementation status, notes and linked policies. Progress shows live on the dashboard.
Why COD, not just a feature
A typical ISMS tool sits next to your operations and needs constant reconciliation. COD uses the same assets for compliance and operations: one data set instead of two versions of the truth. Evidence integrity is built in via database triggers, not maintained by discipline, and three standards plus NIS2 run on one foundation instead of separate silos. All of it on-premises and multi-tenant.
Frequently asked questions
See the GRC module in your environment
A live demo without sales pressure, hands-on in your environment.