ISMS & Security

Complete ISMS on a shared data foundation

Manage, evaluate and evidence risks, vulnerabilities, threats and permissions in Docusnap.

Foundation for ISO/IEC 27001, NIS2 and BSI IT-Grundschutz

Risk Management

Manage risks, vulnerabilities and threats in one place

As a building block for certification under ISO/IEC 27001, NIS2, BSI IT-Grundschutz and beyond, the ISMS module in Docusnap combines risk, vulnerability and threat management on a shared CMDB data foundation.

All security-relevant information comes together in one place in Docusnap. Risks are tied to real assets from the CMDB rather than a separately maintained spreadsheet. Vulnerabilities and threats are mapped to the same objects so that dependencies stay visible. When the audit team reviews, the risk register, action status and evidence are already structured and ready.

AI-Powered

Assess risk posture and action items with AI

Use the Docusnap AI Assistant to analyze your recorded risks, vulnerabilities and actions. The analysis gives you an assessment of your current risk posture and highlights where action is needed, instead of leaving the evaluation to manual review.

What is our current risk posture?

Twelve risks are rated high impact, nine of them with an action in progress. The focus is on access rights and outdated systems.

Which actions are past their target date?

Five actions are past their target date, three of them tied to high-impact risks. Four different owners are involved.

Who has access to the finance drive?

18 accounts across three groups, four of them with full control. Two accounts have been orphaned since the last scan.

Which risks have no owner assigned?

Seven risks currently have no owner. Four of them are tied to assets from the last inventory scan.

Which vulnerabilities affect production servers?

Eleven vulnerabilities affect production servers, three of them rated critical. An action is already in place for two.

Instruments

Three instruments for a working ISMS

IT documentation, security and policies all draw from the same data in Docusnap. One shared inventory across all three domains.

Assets straight from the CMDB

Inventoried IT components are available as protection objects in the ISMS. Hardware, software, network devices and their dependencies come directly from existing documentation.

Policies as guided SmartDocs

Policies and security guidelines are created through a guided process instead of starting with a blank Word document. SmartDocs sit in the ISMS right next to risks and assets.

Risk matrices for assessment

Likelihood and impact are assessed visually in a matrix. The view gives a quick overview of risk distribution and prioritizes where action is needed.

Actions

From derivation to effectiveness review

Every action in Docusnap has an owner, a status and a target date. From derivation from a risk through implementation to the effectiveness review, the entire lifecycle remains traceable. In the next management review or audit, the overview shows at a glance which actions are open, in progress or completed.

Capture risks, derive actions, verify effectiveness.

Permissions Analysis

Who can access what?

When the question of access rights comes up, Docusnap lets you answer it in minutes. The permissions analysis evaluates file, share and group permissions and visualizes inheritance and nested groups. Unintended access becomes visible before it turns into an incident.

By user

Shows all resources a specific person can access. Answers the question: what can this account reach?

By resource

Shows all people and groups that can access a share, folder or mailbox. Answers the question: who has access here?

Frequently asked questions about the ISMS in Docusnap

Does the ISMS cover the requirements of ISO/IEC 27001, NIS2 and BSI IT-Grundschutz?

Docusnap supplies the structural foundation for these frameworks: risk register, action tracking, policies and evidence. Certification itself is carried out by an accredited body. Docusnap prepares the documentation and evidence required for the process.

How does the ISMS module differ from a dedicated GRC tool?

The difference is in the data. GRC tools often capture risks separately from the actual IT infrastructure. In Docusnap, risks are tied to concrete assets from the CMDB. Permissions analysis and IT documentation draw on the same data. The ISMS works on real inventory data rather than manually maintained assumptions.

What evaluations does the permissions analysis provide?

The permissions analysis shows file, share and group permissions from two directions: starting from a user (what can this person access) and starting from a resource (who can access this share). Nested groups and inherited rights are resolved graphically.

How are responsibilities assigned in the ISMS?

Every risk and every action is assigned an owner directly in the ISMS module. The assignment ensures that during audits and reviews it is clear who is responsible for which area. Every action carries a status and a target date.

Are policies created directly in the ISMS?

Docusnap provides guided SmartDocs. Instead of starting with a blank document, a structured workflow guides the creation process. The finished policy sits in the ISMS right next to the associated risks and assets.

Build your ISMS on real data

Try Docusnap and see how risk management, action tracking and permissions analysis work together on a shared data foundation.

Free trial, no commitment