93 controls, four themes, one register.
Organizational
Policies, roles, suppliers, incident management.
People
Awareness, on/offboarding, accountability.
Physical
Access, cabling, disposal, site security.
Technological
Access, hardening, logging, backup, cryptography.
One management system for both.
Quality and information security share the same system and the same living handbook — no second pile of paperwork for the second audit.
Document control
Reviewed, released, versioned — everyone sees the valid version, old ones archived.
Internal audits
Planned, performed, documented — with findings, deadlines and owners.
Actions (CAPA)
Corrective and preventive actions tracked to proven effectiveness.
Non-conformities (NC)
Capture, assess and resolve non-conformities — nothing slips through.
Complaints (8D)
Structured root-cause analysis, prevent recurrence — linked to batch and asset.
Certificates & evidence
Test certificates and certificates per batch and asset — findable at a click.
The handbook behind it is living — one source, automatically in ERP, wiki and AI search. To the living handbook →
Likelihood × impact. Click a risk — the cell lights up, the measure appears.
Measures
You maintain the measure once — the mapping to the standards comes along. No documenting three times for three audits.
NIS2
EU directive for essential & important entities — risk, reporting, supply chain.
BSI IT-Grundschutz
Modules and measures, mappable to the ISO controls.
NIST CSF 2.0
Govern · Identify · Protect · Detect · Respond · Recover.
Seamless technical auditability.
SIEM — intrusion detection
WazuhSuspicious behaviour on servers and clients is detected and alerted.
Metrics & alerts
ZabbixLoad, availability, thresholds — before something fails.
Central logs
GraylogAll log streams in one place, searchable and retained.
Technical auditability
audit trailWho did what when — traceable, tamper-evident.
All self-hosted, all logs in-house. More on data sovereignty →