In COD 3.1, the ISMS was our biggest move yet: ISO 27001 right in the tool instead of in Excel. We've learned a lot since then, above all that in the real world, compliance rarely stops at a single standard.
COD 3.4 draws the obvious conclusion and turns the ISMS into a true GRC platform.
ISMS Becomes GRC
GRC stands for Governance, Risk & Compliance. The name isn't marketing gloss. It describes what the module can do now: not just a management system for one standard, but the integrated interplay of multiple standards, cases, and evidence. The UI is renamed to GRC accordingly, effective immediately.
Multiple Standards on One Data Foundation
At its heart is a versioned multi-standard catalog: ISO/IEC 27001 and 27002, ISO 9001, ISO 22301, and NIS2. On top of that sits a multi-standard Statement of Applicability (SoA) with a merged, cross-standard view. A new standards-matrix widget shows the integrated management system as a matrix: one row per harmonized topic, one column per standard, and in each cell the actual catalog requirements together with the GRC documents that truly implement the topic. Nothing typed by hand. It's all derived from your own data.
Cases, Activities, and an Org Chart
- Cases: Reports, incidents, and findings in one place, including incident SLAs and a dedicated branch for GDPR breach notification under Art. 33.
- Activities: a tracker for audit follow-up. Tasks can be linked to cases, and document control automatically generates review activities.
- Org Chart: an editable org structure right in the tool.
On top of that: a unified document model with two-stage approval, a central glossary, a generic Markdown importer (file, archive, or Git), and PDF reports for standard coverage and document control.
Beyond GRC, Too
- Firewall Self-Registration: Firewalls register themselves via a generic plugin-auth mechanism and wait on an approval page for confirmation.
- Per-Firewall Reachability: Failure threshold, email suppression, snooze, and TCP/ICMP display are now configurable per firewall.
- Security: Firewall API secrets are now stored encrypted in the database.
One more note: as of 3.4, the UI is switched over to English throughout.
Migration
The transition is described in the MIGRATION.md. The backend path stays /isms for compatibility reasons, even though the module is now called GRC.
Want a Live Demo?
If you want to feel what multiple standards on a single foundation are like, get in touch. We'd be happy to show you the GRC platform in action.
Module overview: extoco.de
extocode GmbH · Central Operations Dashboard