Three months ago? Six months ago? Quickly updated just before the last audit?
You're not alone. This isn't a failure – it's a structural problem. Most ISMS tools are compliance instruments that pretend infrastructure stands still. You fill them in once, maintain them half-heartedly, and hope the auditor doesn't dig too deep.
We built COD-ISMS because we face this reality every day. And because it can be done better.
The Real Problem: Two Worlds That Never Meet
Every company has two parallel realities:
Reality 1: The infrastructure. IT systems, OT installations, medical devices, transformer stations, production control systems. It changes constantly. Devices come and go. Configurations change.
Reality 2: The ISMS. Asset lists, risk assessments, controls. Maintained by people, last updated three months ago.
The gap between these two worlds is the blind spot of every traditional ISMS. And that is exactly where attackers strike – and auditors, too.
COD closes this gap. Automatically.
COD is an integrated platform of several modules that mesh together seamlessly:
Layer 1: COD-Network – Network Inventory as the Starting Point
COD-Network automatically detects all IP-addressable devices on the network – from IT endpoints and network components to OT systems and industrial equipment, as long as they are reachable over the network. Network topology plans are created and imported.
What COD-Network does not do yet: it does not classify assets automatically. The categorization – what is a firewall, what is a PLC, what is a medical device – is done manually. Honestly, that makes sense: anyone who knows their own infrastructure wants to make that decision themselves.
Layer 2: COD-ISMS – Structured Compliance on Live Data
COD-ISMS takes the assets maintained in COD-Network and turns them into the basis for a structured, documented ISMS.
What that means in practice:
Manage controls, not just tick them off. All 93 ISO 27001:2022 Annex A controls are included, grouped into four topic areas. For each control you record applicability (yes/no), implementation status (implemented / partial / planned / not implemented), notes, and linked policies. You can see progress visually in the dashboard.
Policies that are truly part of compliance. Policies are linked directly to the corresponding controls – versioned, with diff view, and a continuous workflow from draft to archived.
An audit trail worthy of the name. Every change – to assets, controls, policies, risk assessments – is logged completely. Who, when, what, where, why. Tamper-proof and signed server-side. This is the traceability foundation for external audits.
Risk assessments on the actual asset. Not on a generic "network component," but on the specific asset – with the live status that COD-Network provides.
An audit trail worthy of the name. Every change is logged completely. Who, when, what, where, why. Tamper-proof and signed server-side.
On-Premises or Cloud – Both Options, Full Control
Especially in KRITIS environments, "no data in the cloud" is often not a preference but a requirement. COD runs entirely on-premises – on your infrastructure, in your data center.
And yet: template updates – new ISO controls, an updated BSI catalog, policy templates – are provided centrally and can be applied in a controlled way. No forced cloud. No outdated content.
Who COD-ISMS Was Built For
For IT managers who have no time to maintain asset lists manually – and still need a clean, documented ISMS foundation.
For CISOs who want to know: which controls are documented as implemented, and which are still open? – and who want an answer based on an up-to-date asset inventory.
For managing directors operating in regulated environments who have understood: an ISMS that does not match reality is not protection. It is a liability issue.
Conclusion: An ISMS That Knows What It Protects – and Honestly States What It Can Do
Most ISMS tools know what you told them – months ago. COD combines network inventory and compliance documentation in one platform – without manual bridges, without duplicate data entry.
If you'd like to see what this looks like in your environment – we'll gladly show you. Hands-on, no sales pressure, no 47-page quote up front.
