GRC that knows what it protects
Governance, Risk & Compliance (GRC), your central management system for information security, quality and business continuity – on live data.
Most GRC tools act as if your infrastructure stood still – filled in once and current as of months ago. That's exactly where attackers and auditors strike. The COD GRC module closes this gap because it works on the same live asset data as your operations, and makes your NIS2 readiness demonstrable.
From infrastructure to compliance
COD automatically detects every IP-addressable device, from IT to network to OT. The GRC module uses exactly these maintained assets as the basis for a structured, documented management system.
- No duplicate data maintenance, no manually built bridges
- Risks are tied to the specific asset including its live status
- One truth for operations and compliance
Multiple standards, one management system
Whether information security, quality or business continuity, the GRC module covers the leading standards on a shared data base.
ISO 27001
Information security including all 93 Annex A controls
ISO 9001
Quality management
ISO 22301
Business Continuity Management
BSI 200-3
Risk-based methodology per IT-Grundschutz
Manage controls, don't just check them off
- All 93 ISO 27001 Annex A controls, grouped into four themes
- Per control: applicability, implementation status, notes, linked policies
- Progress visible in the dashboard at any time
Policies and risks on live data
- Policies linked to controls, versioned, with diff and workflow
- Risk assessment asset-based and versioned, with BSI 200-3 defaults
- The specific asset is assessed, including its live status
An audit trail worthy of the name
- Every change logged without gaps: who, when, what, where, why
- Append-only, tamper-proof via database triggers and signed
- A dedicated, separate PostgreSQL database for compliance data
On-premises, with up-to-date content
Especially in KRITIS environments, "no data in the cloud" is a requirement, not a preference. COD runs entirely on-premises, and you retain full control of your data.
- Full data sovereignty, KRITIS-ready, NIS2-oriented
- Template updates for new ISO controls and the BSI catalog can be provided centrally
Frequently asked questions
See the GRC module in your environment
A live demo without sales pressure, hands-on in your environment.