Compliance · quality & security

Security you can actually show.

A living ISMS to ISO 27001:2022 — with risk register, measures and evidence. NIS2, BSI and NIST all speak the same language: one control, many frameworks.

§01 · ISO 27001:2022 — Annex A

93 controls, four themes, one register.

37

Organizational

Policies, roles, suppliers, incident management.

8

People

Awareness, on/offboarding, accountability.

14

Physical

Access, cabling, disposal, site security.

34

Technological

Access, hardening, logging, backup, cryptography.

Quality management · ISO 9001

One management system for both.

Quality and information security share the same system and the same living handbook — no second pile of paperwork for the second audit.

Document control

Reviewed, released, versioned — everyone sees the valid version, old ones archived.

Internal audits

Planned, performed, documented — with findings, deadlines and owners.

Actions (CAPA)

Corrective and preventive actions tracked to proven effectiveness.

Non-conformities (NC)

Capture, assess and resolve non-conformities — nothing slips through.

Complaints (8D)

Structured root-cause analysis, prevent recurrence — linked to batch and asset.

Certificates & evidence

Test certificates and certificates per batch and asset — findable at a click.

The handbook behind it is living — one source, automatically in ERP, wiki and AI search. To the living handbook →

§02 · Risk heatmap

Likelihood × impact. Click a risk — the cell lights up, the measure appears.

Impact →
5
1
4
2
6
3
Likelihood →

Likelih. /5 Impact /5 Score

Measures

§03 · One control, many frameworks

You maintain the measure once — the mapping to the standards comes along. No documenting three times for three audits.

NIS2

EU directive for essential & important entities — risk, reporting, supply chain.

BSI IT-Grundschutz

Modules and measures, mappable to the ISO controls.

NIST CSF 2.0

Govern · Identify · Protect · Detect · Respond · Recover.

§04 · See what happens — and prove it

Seamless technical auditability.

SIEM — intrusion detection

Wazuh

Suspicious behaviour on servers and clients is detected and alerted.

Metrics & alerts

Zabbix

Load, availability, thresholds — before something fails.

Central logs

Graylog

All log streams in one place, searchable and retained.

Technical auditability

audit trail

Who did what when — traceable, tamper-evident.

All self-hosted, all logs in-house. More on data sovereignty →

Is NIS2 coming — or are you ready?

An ISMS isn't a binder, it's a running operation. We set it up so it holds.

Send pain list → And if something does happen? ↗