Cybervize
ISMS module of OdySecure, the security platform from Cybervize

ISMS software for ISO 27001 and NIS-2, built for the European mid-market

ISMS operations with organisational structure, BIA, incident management, asset inventory, dual risk assessment, measure tracking and Statement of Applicability, all in one platform, sharing data with BCM, TPRM and Assessment. Hosted in Germany.

Request an ISMS module demo

What the ISMS module covers

The ISMS module implements ISO 27001:2022 as an operating system. No Excel spreadsheet, no Word manual.

Organisational structure

Scope, roles, ISMS committee, responsibility matrix. Default templates per ISO 27001:2022 or customisable to existing organisational charts.

Asset inventory with dependency graph

Assets, asset owners, data classification, dependencies across applications, servers and suppliers. Cross-module data flow to BCM (BIA) and TPRM (supplier risk).

Dual risk assessment

Inherent vs. residual risk with measure linkage. Likelihood and impact per customer-specific matrix. Acceptance workflow with four-eyes principle.

Measure tracking and Statement of Applicability

ISO 27001 Annex A controls from assessments or audits, measure maintenance, deadline and responsibility tracking. Statement of Applicability auto-generated.

Incident management with reporting obligations

Incident registration, classification, escalation. GDPR 72-hour deadline, NIS-2 reporting obligations (24h early warning, 72h incident report, one-month final report), KRITIS reports. Templates with data fields for the responsible authorities.

Management review and reporting

Auto-populated KPIs from live ISMS operations. Templates for board reporting, supervisory board, auditors and insurers. Snapshots for auditors with revision-safe versioning.

What dual risk assessment looks like

The same register in three views: residual risk after controls, current state from evidence, inherent risk before. The configured risk appetite marks what is accepted and what escalates.

Risk heatmap in OdySecure: 5x5 grid of likelihood and impact with 60 risks, 51 of them assessed and placed in the grid, plus the count by severity and the marked risk appetite

Behind it sits the register itself. Every risk carries its origin: NIST SP 800-82, MITRE ATT&CK ICS, ENISA Threat Landscape, or an incident of your own. The figures at the top say what sits above appetite and what has no treatment yet.

Risk register in OdySecure: list of 60 risks with score and source per entry, including NIST SP 800-82 and MITRE ATT&CK ICS, alongside the graph of linked objects

Clicking a risk highlights its causal chain: which assets it affects, which controls act on it, and which standard it hangs from. That is the difference between a list and a register that can answer questions.

Causal chain of a risk in OdySecure: the selected risk is linked in the graph to the affected OT assets, the controls that act on it, and the NIST SP 800-82 standard

No CISO of your own?

In a vCISO mandate, your vCISO works with OdySecure and the platform is included. From €3,600/month.

Still comparing? The honest comparison of the four ways to ISO 27001 shows when Excel, a point tool or a GRC suite is the better way.

More about the ISMS module

From Excel to your certification audit

The ISMS module takes your management system from first inventory to audit-ready evidence in eight steps, and then into continuous operation. Each step is created in the platform, not in spreadsheets and Word manuals.

Asset register in OdySecure: ten assets with catalogue taxonomy, protection needs for confidentiality, integrity and availability, status and the responsible unit.
01

Scope and organisation

Set up scope, roles, ISMS committee and responsibility matrix to ISO 27001:2022, from templates or adapted to your existing structure.

02

Assets and information values

Asset inventory with owners, data classification and a dependency graph. The same data feeds BCM (BIA) and third-party risk (TPRM).

03

Gap assessment

Capture your current state against ISO 27001 Annex A, maturity per control and a prioritised gap list, from the Assessment module.

04

Assess risks

Dual assessment of inherent and residual risk on your own matrix, with a four-eyes acceptance workflow.

05

Select controls and build the SoA

Choose and justify Annex A controls; the Statement of Applicability is generated automatically from those decisions.

06

Manage actions and evidence

Actions with due dates and owners, evidence status per control. Progress stays visible at all times.

07

Internal audit and management review

KPIs fill automatically from live operation; templates for internal audit, management review and board reporting.

08

Auditor snapshot and operation

Export a tamper-evident snapshot for the certification body; the platform then keeps operating the ISMS continuously.

How long does what take?

Three milestones, three timelines. The numbers describe different things, not one contradictory range.

Migrating existing content

Import a grown Word/Excel ISMS via the assessment module with OSCAL import, including handover of maintenance to internal owners.

6 to 10 weeks
Audit-ready operation

Under a vCISO mandate, a senior CISO leads the rollout from first inventory to certification-ready operation and works with this module.

6 to 9 months
Onboarding project to self-service

Platform licence, with an onboarding project if you want one; after that, your internal team runs the platform itself.

6 to 12 months

What incident handling looks like

Open incidents grouped by due date, with severity, ID, owner and status. From the software, not a mock-up.

Security incidents in OdySecure: two critical incidents due today, one medium due soon, each with ID, owner and status

Standards and frameworks covered by the ISMS module

The ISMS module covers the ISO 27001 family and integrates the complementary standards relevant for DACH. No fragmented multi-tool architecture.

  • ISO/IEC 27001:2022 as the main standard including Annex A and Statement of Applicability
  • ISO/IEC 27002:2022 as control reference
  • NIS-2 minimum measures per German BSIG § 30, mapped to ISO 27001 controls
  • GDPR obligations (TOMs, processing records, 72-hour reporting) integrated
  • BSI IT-Grundschutz: building blocks via OSCAL import from the Assessment module
  • KRITIS reporting and evidence obligations per German BSIG §§ 32 and 39
  • DORA-relevant controls for financial service providers
50frameworks as a catalogue in the platform:standards and frameworks, regulatory requirements, requirement records per entry.See the full list

Who the ISMS module is built for

Three constellations in which the ISMS module replaces the Excel-Word-SharePoint approach economically.

Mid-market companies before first ISO 27001 certification

200 to 500 employees, NIS-2 affected, wants to certify rather than merely be compliant. Without in-house ISMS practice: under a vCISO mandate, a senior CISO leads the rollout through to the audit and works with this module; the platform is included in the mandate. Audit-ready in 6 to 9 months.

About the vCISO mandate

Enterprises with existing ISMS and tool migration

Existing Excel/Word/SharePoint solution grown organically, multi-site hard to map, auditors challenge revision safety. Migration via the Assessment module: existing controls imported, gaps flagged, maintenance from day 1 in the platform.

Consultancies with multiple clients

vCISO consultancies with 5 to 30 clients need multi-tenancy without mixing data. ISMS module with strict tenant isolation, RBAC for cross-client consultant view, without cross-contamination.

FAQ about the ISMS module

What is the difference between an ISMS tool and an ISMS platform?
An ISMS tool is stand-alone software covering only the information security management system. An ISMS platform integrates ISMS with related disciplines such as BCM, TPRM and Assessment on one data layer. Benefit: BIA data automatically validates BCM plans, from assessment gaps you create ISMS measures with one click, critical suppliers create BCM threat scenarios. In a pure ISMS software, these links only happen via manual synchronisation or not at all.
Which ISO 27001 version does the ISMS module support?
ISO/IEC 27001:2022 as main standard, including Annex A with 93 controls in four theme areas. Migration from 2013 implementations is supported via mapping templates. ISO 27002:2022 serves as control reference.
How does the ISMS module support NIS-2 concretely?
The ten minimum measures per German BSIG § 30 are pre-configured as mandatory controls and mapped to ISO 27001 Annex A, so no duplicate effort. The NIS-2 reporting obligations (24-hour early warning, 72-hour incident report, one-month final report) are built into the Incident Management workflow. For the board there is a management briefing template covering liability and effectiveness control. The legal assessment of NIS-2 affectedness remains with a law firm; the ISMS module delivers the operational implementation.
Can we migrate existing ISMS content from Excel or Word?
Yes, via the Assessment module with OSCAL import. What is read in is your catalogue: controls, sections and questions become an assessment framework that you then work through. Existing risks and measures are not carried over by this route; they arise from the answers. Typical migration from a grown Word/Excel ISMS takes six to ten weeks, including handover to internal responsibilities.
Who can operate the ISMS module without external consulting?
Organisations with their own ISO or CISO and their own ISO 27001 practice operate the module independently after a two- to four-week onboarding phase. Without in-house ISMS practice: under a vCISO mandate, a senior CISO leads the rollout through to the audit and works with this module; the platform is included in the mandate. If you want to run the module yourself, you get the platform licence, with an onboarding project if you want one.
Where is the ISMS hosted?
Hosting of the platform and processing of your data within it exclusively in data centers in Germany, with a European provider without a US parent company, which under current law is not subject to the US CLOUD Act. AI models are operated in sovereign mode without data sharing with external model providers; in BYOK mode you connect your own provider, and the content sent to it leaves this scope. GDPR-compliant with JSON data export that marks its own limits and scheduled data deletion.

ISMS is one module of OdySecure

The ISMS module shares the data layer, permission model and audit trail with the BCM module (Business Continuity, ISO 22301), TPRM (third-party risk management) and Assessment (OSCAL import and custom catalogues). There are no mandatory modules: licensing is modular, modules build on each other without forcing each other.

See the full platform

Memberships, programmes and partnerships

  • BSI Allianz für Cyber-Sicherheit
  • CISPA Helmholtz-Zentrum für Informationssicherheit
  • TeleTrusT - Bundesverband IT-Sicherheit
  • IT Security Made in Germany - TeleTrusT