ISMS · ISO 27001 · BSI IT-Grundschutz

ISMS software that builds on your CMDB – not beside it.

Ordivis Security

Most ISMS tools demand an inventory of their own. You then maintain two truths, and one of them is always out of date. Ordivis Platform keeps protection requirements, the Grundschutz check and the risk analysis directly on the configuration items – for BSI IT-Grundschutz and ISO/IEC 27001:2022 in the same module.

2 frameworks, one module 72 threats in the catalogue BSI 200-3 risk analysis
# From target object to control
CI: app-srv-04  (CI class: Windows server)
 └─ Suggestion  SYS.1.2.3 Windows Server
     ├─ Requirement  Target / actual / not applicable
     ├─ Risk  Frequency × damage → 1–25
     └─ Control  Deadline · owner · status

Source:  CMDB (read-only)
Closure: audit-proof, PDF report
Fundamentals

What is an ISMS?

A ISMS (information security management system) is the documented body of procedures, responsibilities and controls with which an organisation systematically manages information security – from protection requirements through risk assessment to the review of effectiveness.

Important for expectations: an ISMS is not a product you buy but a management system you run. Software can support it – by holding catalogues, tracking progress, monitoring deadlines and producing evidence. No tool takes the decisions about which risk is acceptable off your hands.

What software very much does have to achieve: stopping the effort from draining away into document management. An ISMS consisting of 40 Word files and three spreadsheets holds up at the first audit and is out of date a year later.

ISO 27001 or BSI IT-Grundschutz?

ISO/IEC 27001 describes what an ISMS has to achieve and leaves largely open how. The BSI IT-Grundschutz instead supplies concrete building blocks with fully worded requirements per type of target object and is thus considerably more prescriptive – you work through a structure rather than inventing one.

In practice the environment usually decides: in the German public sector and among critical infrastructure operators Grundschutz is widespread, while internationally there is no way past ISO 27001. The two are not mutually exclusive – a Grundschutz certification includes an ISO 27001 certificate. Ordivis Platform therefore keeps both catalogues in the same module instead of tying you to one framework.

Who needs an ISMS?

Mandatory for critical infrastructure operators and for entities within the scope of NIS2, effectively compelled by many public tenders and in the supply chains of large industrial customers. Voluntarily sensible as soon as the loss or leakage of data seriously hurts the business – so practically everywhere.

Approach

The path from the CMDB to the audit report

This is how Ordivis Platform maps the Grundschutz cycle – each step builds on the previous one without any data having to be entered again.

  1. Load the catalogue

    Security catalogues are imported via OSCAL – BSI IT-Grundschutz as well as ISO/IEC 27001:2022 Annex A. The catalogue browser is editable and extensible; you can add requirements of your own.

  2. Structure analysis from the CMDB

    The target objects come from the CMDB – read-only, so that the ISMS opens no competing inventory. No second stock list, no reconciliation.

  3. Modelling

    Building blocks are assigned to target objects. Based on the CI class Ordivis Platform suggests the matching blocks automatically – which spares you most of the dull assignment work.

  4. IT-Grundschutz check

    The target/actual comparison is kept per requirement, with the implementation status yes / partly / no / not applicable and a justification. Progress is visible as a percentage at any time, not only at the end.

  5. Risk analysis under BSI 200-3

    From a catalogue of 47 BSI elementary threats and 25 enterprise threats risks are derived and rated by frequency × damage on a scale from 1 to 25. Once the treatment strategy has been chosen the residual risk is rated again – both states appear in a 5×5 heat map.

  6. Control plan

    Open requirements and unaccepted risks automatically produce a control plan with ownership, deadline and status tracking. Critical risks trigger a notification to the information security officer.

  7. Audit closure & report

    The closure is audit-proof: the state is frozen and remains traceable. A management summary, risk register, control plan and protection requirement overview are produced as PDF – along with a delta reportshowing the progress between two checks.

Feature scope

What the ISMS module contains

No add-on module, no surcharge – the ISMS is part of the full feature set of every licence.

  • Security catalogue import (OSCAL / BSI IT-Grundschutz)
  • Catalogue browser, editable and extensible
  • ISO/IEC 27001:2022 Annex A in the same module
  • Modelling: assigning building blocks to target objects
  • Automatic building block suggestion based on the CI class
  • IT-Grundschutz check (target/actual per requirement)
  • Implementation status yes / partly / no / not applicable
  • Automatic control plan with status tracking
  • Audit-proof audit closure
  • Risk analysis under BSI 200-3 (frequency × damage, 1–25)
  • Treatment strategy, residual risk & risk acceptance by the information security officer
  • Graphical 5×5 risk heat map (gross and residual risk)
  • Notification on critical risk
  • Threat catalogue: 47 elementary threats + 25 enterprise threats
  • Reports as PDF: management summary, risk register, control plan, protection requirements
  • ISMS dashboard: protection requirements, check progress & risk position per information domain
  • delta report between two Grundschutz checks
  • CI tab „information security“ with a review notice on decommissioning
  • A dedicated information security officer role (ISB, Informationssicherheitsbeauftragter)
  • Fine-grained security.* permissions
  • Evidence for A.8.13 information backup: backup plans, target/actual comparison, logged review periods and restore tests hang directly on the control and the SoA entry – backup in detail
  • Single sign-on as a contribution to IAM evidence: an OIDC broker with no secret in the client, enforced PKCE and nightly reconciliation with the sign-in service
The difference

Why a standalone ISMS tool gets expensive

No second inventory

Separate ISMS tools need target objects of their own. Someone maintains them carefully at the start – and after a year nobody does. Ordivis Platform reads the CMDB instead of copying it.

Changes get noticed

If a linked CI is decommissioned, the information security officer receives a review notice. The security picture then ages visibly rather than silently.

Controls become tickets

Open controls run in the same system as the Service desk. No export to Excel, no parallel tracking by e-mail.

BCM draws on the same data

Business continuity management, emergency planning and disaster recovery use the same CIs and protection requirements – the BIA does not have to survey the landscape again.

Data protection under the same roof

The record of processing activities under Art. 30 GDPR sits in the same system. Technical and organisational measures do not have to be documented twice.

One audit trail

Changes to security data go through the same audit logging as everything else – one body of evidence instead of several partial logs.

Frequently asked questions about the ISMS

Answered briefly and honestly

What is an ISMS?

An ISMS (information security management system) is the documented body of procedures, responsibilities and controls with which an organisation systematically manages information security – from protection requirements through risk assessment to the review of effectiveness. It is not a product but a management system; software supports it but does not replace it.

What is the difference between ISO 27001 and BSI IT-Grundschutz?

ISO/IEC 27001 describes what an ISMS has to achieve and leaves open how. BSI IT-Grundschutz supplies concrete building blocks with fully worded requirements per type of target object and is thus considerably more prescriptive. In Germany Grundschutz is widespread in the public sector and among critical infrastructure operators, ISO 27001 internationally. The two can be combined – a Grundschutz certification includes an ISO 27001 certificate.

Which frameworks does Ordivis Platform support?

BSI IT-Grundschutz and ISO/IEC 27001:2022 Annex A are kept in the same module. Security catalogues can be imported via OSCAL and the catalogue browser is editable and extensible – so your own or sector-specific catalogues can be represented as well.

Why should the ISMS build on the CMDB?

Because otherwise two inventories have to be maintained and they drift apart. In Ordivis Platform the ISMS uses the CMDB read-only as the basis for its target objects: building blocks are suggested automatically from the CI class, and when a linked CI is decommissioned the information security officer receives a review notice.

How does the risk analysis under BSI 200-3 work?

Risks are derived from a catalogue of 47 BSI elementary threats and 25 additional enterprise threats and rated by frequency × extent of damage on a scale from 1 to 25. Once the treatment strategy has been chosen the residual risk is rated again; both states appear in a graphical 5×5 heat map. Risk acceptance is performed by the information security officer, and critical risks trigger a notification.

Does the software help with NIS2?

Indirectly – and we put that cautiously on purpose. NIS2 requires risk management, measures to keep operations running, reporting channels and the ability to produce evidence. Those are exactly the building blocks Ordivis Platform supplies with the ISMS, BCM and the audit-proof trail. A tool does not, however, satisfy a directive – implementation remains an organisational task.

Does the ISMS software run on premises?

Yes, and here in particular it matters: the data contains protection requirements, open controls and assessed weaknesses – a map of your attack surface. Ordivis Platform runs entirely in your own data centre on PostgreSQL, and thanks to ECDSA offline activation air-gapped without an internet connection too.

Does this replace a certification?

No. It is your organisation that gets certified by an accredited body, not your software. Ordivis Platform supplies the structure, the evidence and the reports you take into an audit – the assessment is made by the auditor.

Related

Security needs inventory data

CMDB software

The basis for target objects: configuration items, relations and impact analysis as the foundation of every structure analysis.

ITSM software

Every ITIL module on the same data basis – so that controls land in operations and not in a side list.

BCM software

Continuity gaps from the BIA move straight into the ISMS risk analysis as risks.

Record of processing activities

Art. 30 GDPR in the same system – no need to document technical and organisational measures twice.

Municipal & critical infrastructure

Why Grundschutz, budget predictability and air-gapped operation belong together for public administrations.

See the Grundschutz cycle on real data.

From modelling through the check to the heat map – in a demo by video conference, with the current state of development.