Ordivis Security
Most ISMS tools demand an inventory of their own. You then maintain two truths, and one of them is always out of date. Ordivis Platform keeps protection requirements, the Grundschutz check and the risk analysis directly on the configuration items – for BSI IT-Grundschutz and ISO/IEC 27001:2022 in the same module.
# From target object to control CI: app-srv-04 (CI class: Windows server) └─ Suggestion SYS.1.2.3 Windows Server ├─ Requirement Target / actual / not applicable ├─ Risk Frequency × damage → 1–25 └─ Control Deadline · owner · status Source: CMDB (read-only) Closure: audit-proof, PDF report
A ISMS (information security management system) is the documented body of procedures, responsibilities and controls with which an organisation systematically manages information security – from protection requirements through risk assessment to the review of effectiveness.
Important for expectations: an ISMS is not a product you buy but a management system you run. Software can support it – by holding catalogues, tracking progress, monitoring deadlines and producing evidence. No tool takes the decisions about which risk is acceptable off your hands.
What software very much does have to achieve: stopping the effort from draining away into document management. An ISMS consisting of 40 Word files and three spreadsheets holds up at the first audit and is out of date a year later.
ISO/IEC 27001 describes what an ISMS has to achieve and leaves largely open how. The BSI IT-Grundschutz instead supplies concrete building blocks with fully worded requirements per type of target object and is thus considerably more prescriptive – you work through a structure rather than inventing one.
In practice the environment usually decides: in the German public sector and among critical infrastructure operators Grundschutz is widespread, while internationally there is no way past ISO 27001. The two are not mutually exclusive – a Grundschutz certification includes an ISO 27001 certificate. Ordivis Platform therefore keeps both catalogues in the same module instead of tying you to one framework.
Mandatory for critical infrastructure operators and for entities within the scope of NIS2, effectively compelled by many public tenders and in the supply chains of large industrial customers. Voluntarily sensible as soon as the loss or leakage of data seriously hurts the business – so practically everywhere.
This is how Ordivis Platform maps the Grundschutz cycle – each step builds on the previous one without any data having to be entered again.
Security catalogues are imported via OSCAL – BSI IT-Grundschutz as well as ISO/IEC 27001:2022 Annex A. The catalogue browser is editable and extensible; you can add requirements of your own.
The target objects come from the CMDB – read-only, so that the ISMS opens no competing inventory. No second stock list, no reconciliation.
Building blocks are assigned to target objects. Based on the CI class Ordivis Platform suggests the matching blocks automatically – which spares you most of the dull assignment work.
The target/actual comparison is kept per requirement, with the implementation status yes / partly / no / not applicable and a justification. Progress is visible as a percentage at any time, not only at the end.
From a catalogue of 47 BSI elementary threats and 25 enterprise threats risks are derived and rated by frequency × damage on a scale from 1 to 25. Once the treatment strategy has been chosen the residual risk is rated again – both states appear in a 5×5 heat map.
Open requirements and unaccepted risks automatically produce a control plan with ownership, deadline and status tracking. Critical risks trigger a notification to the information security officer.
The closure is audit-proof: the state is frozen and remains traceable. A management summary, risk register, control plan and protection requirement overview are produced as PDF – along with a delta reportshowing the progress between two checks.
No add-on module, no surcharge – the ISMS is part of the full feature set of every licence.
security.* permissionsSeparate ISMS tools need target objects of their own. Someone maintains them carefully at the start – and after a year nobody does. Ordivis Platform reads the CMDB instead of copying it.
If a linked CI is decommissioned, the information security officer receives a review notice. The security picture then ages visibly rather than silently.
Open controls run in the same system as the Service desk. No export to Excel, no parallel tracking by e-mail.
Business continuity management, emergency planning and disaster recovery use the same CIs and protection requirements – the BIA does not have to survey the landscape again.
The record of processing activities under Art. 30 GDPR sits in the same system. Technical and organisational measures do not have to be documented twice.
Changes to security data go through the same audit logging as everything else – one body of evidence instead of several partial logs.
An ISMS (information security management system) is the documented body of procedures, responsibilities and controls with which an organisation systematically manages information security – from protection requirements through risk assessment to the review of effectiveness. It is not a product but a management system; software supports it but does not replace it.
ISO/IEC 27001 describes what an ISMS has to achieve and leaves open how. BSI IT-Grundschutz supplies concrete building blocks with fully worded requirements per type of target object and is thus considerably more prescriptive. In Germany Grundschutz is widespread in the public sector and among critical infrastructure operators, ISO 27001 internationally. The two can be combined – a Grundschutz certification includes an ISO 27001 certificate.
BSI IT-Grundschutz and ISO/IEC 27001:2022 Annex A are kept in the same module. Security catalogues can be imported via OSCAL and the catalogue browser is editable and extensible – so your own or sector-specific catalogues can be represented as well.
Because otherwise two inventories have to be maintained and they drift apart. In Ordivis Platform the ISMS uses the CMDB read-only as the basis for its target objects: building blocks are suggested automatically from the CI class, and when a linked CI is decommissioned the information security officer receives a review notice.
Risks are derived from a catalogue of 47 BSI elementary threats and 25 additional enterprise threats and rated by frequency × extent of damage on a scale from 1 to 25. Once the treatment strategy has been chosen the residual risk is rated again; both states appear in a graphical 5×5 heat map. Risk acceptance is performed by the information security officer, and critical risks trigger a notification.
Indirectly – and we put that cautiously on purpose. NIS2 requires risk management, measures to keep operations running, reporting channels and the ability to produce evidence. Those are exactly the building blocks Ordivis Platform supplies with the ISMS, BCM and the audit-proof trail. A tool does not, however, satisfy a directive – implementation remains an organisational task.
Yes, and here in particular it matters: the data contains protection requirements, open controls and assessed weaknesses – a map of your attack surface. Ordivis Platform runs entirely in your own data centre on PostgreSQL, and thanks to ECDSA offline activation air-gapped without an internet connection too.
No. It is your organisation that gets certified by an accredited body, not your software. Ordivis Platform supplies the structure, the evidence and the reports you take into an audit – the assessment is made by the auditor.
The basis for target objects: configuration items, relations and impact analysis as the foundation of every structure analysis.
Every ITIL module on the same data basis – so that controls land in operations and not in a side list.
Continuity gaps from the BIA move straight into the ISMS risk analysis as risks.
Art. 30 GDPR in the same system – no need to document technical and organisational measures twice.
Why Grundschutz, budget predictability and air-gapped operation belong together for public administrations.
From modelling through the check to the heat map – in a demo by video conference, with the current state of development.