Skip to Content
  •  +49 (861) 88 00 32 00
COD powered by extocode GmbH
  • 0
  • Sign in
  • Contact Us
  • Home
  • COD Overview
    Platform
    OverviewFeaturesIntegrationsPricing
    Operations & Network
    MonitoringNetworkNetwork Access Control (NAC)Captive PortalFirewall
    Security & Resilience
    Governance, Risk & ComplianceVulnerabilities (VAS)BackupHypervisorOTPAutomation
    Solutions & More
    NIS2 & CompliancecodPassLive demoReferencesDownloadsFAQ
  • Pricing
  • News
  • FAQ
  • About us
    • About us
    • Careers
    • References
  • Contact
COD powered by extocode GmbH
  • 0
    • Home
    • COD Overview
    • Pricing
    • News
    • FAQ
    • About us
      • About us
      • Careers
      • References
    • Contact
  •  +49 (861) 88 00 32 00
  • Sign in
  • Contact Us

Why Your ISMS Has No Idea What Your Infrastructure Looks Like – and How to Fix That

Be honest: How old is the asset list in your ISMS?
  • All Blogs
  • News
  • Why Your ISMS Has No Idea What Your Infrastructure Looks Like – and How to Fix That
  • April 9, 2026 by
    Why Your ISMS Has No Idea What Your Infrastructure Looks Like – and How to Fix That
    Verwaltung, extocode GmbH

    Three months ago? Six months ago? Quickly updated just before the last audit?

    You're not alone. This isn't a failure – it's a structural problem. Most ISMS tools are compliance instruments that pretend infrastructure stands still. You fill them in once, maintain them half-heartedly, and hope the auditor doesn't dig too deep.

    We built COD-ISMS because we face this reality every day. And because it can be done better.

    The Real Problem: Two Worlds That Never Meet

    Every company has two parallel realities:

    Reality 1: The infrastructure. IT systems, OT installations, medical devices, transformer stations, production control systems. It changes constantly. Devices come and go. Configurations change.

    Reality 2: The ISMS. Asset lists, risk assessments, controls. Maintained by people, last updated three months ago.

    The gap between these two worlds is the blind spot of every traditional ISMS. And that is exactly where attackers strike – and auditors, too.

    COD closes this gap. Automatically.

    COD is an integrated platform of several modules that mesh together seamlessly:

    Layer 1: COD-Network – Network Inventory as the Starting Point

    COD-Network automatically detects all IP-addressable devices on the network – from IT endpoints and network components to OT systems and industrial equipment, as long as they are reachable over the network. Network topology plans are created and imported.

    What COD-Network does not do yet: it does not classify assets automatically. The categorization – what is a firewall, what is a PLC, what is a medical device – is done manually. Honestly, that makes sense: anyone who knows their own infrastructure wants to make that decision themselves.

    Layer 2: COD-ISMS – Structured Compliance on Live Data

    COD-ISMS takes the assets maintained in COD-Network and turns them into the basis for a structured, documented ISMS.


    What that means in practice:

    Manage controls, not just tick them off. All 93 ISO 27001:2022 Annex A controls are included, grouped into four topic areas. For each control you record applicability (yes/no), implementation status (implemented / partial / planned / not implemented), notes, and linked policies. You can see progress visually in the dashboard.

    Policies that are truly part of compliance. Policies are linked directly to the corresponding controls – versioned, with diff view, and a continuous workflow from draft to archived.

    An audit trail worthy of the name. Every change – to assets, controls, policies, risk assessments – is logged completely. Who, when, what, where, why. Tamper-proof and signed server-side. This is the traceability foundation for external audits.

    Risk assessments on the actual asset. Not on a generic "network component," but on the specific asset – with the live status that COD-Network provides.

    An audit trail worthy of the name. Every change is logged completely. Who, when, what, where, why. Tamper-proof and signed server-side.

    PreviousNext

    On-Premises or Cloud – Both Options, Full Control

    Especially in KRITIS environments, "no data in the cloud" is often not a preference but a requirement. COD runs entirely on-premises – on your infrastructure, in your data center.

    And yet: template updates – new ISO controls, an updated BSI catalog, policy templates – are provided centrally and can be applied in a controlled way. No forced cloud. No outdated content.

    Who COD-ISMS Was Built For

    For IT managers who have no time to maintain asset lists manually – and still need a clean, documented ISMS foundation.

    For CISOs who want to know: which controls are documented as implemented, and which are still open? – and who want an answer based on an up-to-date asset inventory.

    For managing directors operating in regulated environments who have understood: an ISMS that does not match reality is not protection. It is a liability issue.

    Conclusion: An ISMS That Knows What It Protects – and Honestly States What It Can Do

    Most ISMS tools know what you told them – months ago. COD combines network inventory and compliance documentation in one platform – without manual bridges, without duplicate data entry.

    If you'd like to see what this looks like in your environment – we'll gladly show you. Hands-on, no sales pressure, no 47-page quote up front.



    Yes, let's do a demo!


    in News
    # Asset COD COD-ISMS ISMS Kontrolle
    Why Your ISMS Has No Idea What Your Infrastructure Looks Like – and How to Fix That
    Verwaltung, extocode GmbH April 9, 2026
    Share this post
    Stichwörter
    Asset COD COD-ISMS ISMS Kontrolle
    Our blogs
    • News
    • Success Stories
    Archive
    Folgen Sie uns
    ​
    • COD Overview
    • Features
    • Pricing
    • Integrations
    • NIS2
    • codPass
    • References
    • Downloads
    • FAQ
    • Contact

    Kotzinger Straße 21 • 83278 Traunstein • Deutschland

    • ​+49 (861) 88 00 32 00
    • ​info@extoco.de
    Datenschutz Impressum ​
    Copyright © extocode GmbH
    English (US) Français Deutsch Español Türkçe

    We use cookies to provide you a better user experience on this website. Privacy Policy

    Decline Accept