ISMS & Security
Complete ISMS on a shared data foundation
Manage, evaluate and evidence risks, vulnerabilities, threats and permissions in Docusnap.
Foundation for ISO/IEC 27001, NIS2 and BSI IT-Grundschutz
Risk Management
Manage risks, vulnerabilities and threats in one place
As a building block for certification under ISO/IEC 27001, NIS2, BSI IT-Grundschutz and beyond, the ISMS module in Docusnap combines risk, vulnerability and threat management on a shared CMDB data foundation.
All security-relevant information comes together in one place in Docusnap. Risks are tied to real assets from the CMDB rather than a separately maintained spreadsheet. Vulnerabilities and threats are mapped to the same objects so that dependencies stay visible. When the audit team reviews, the risk register, action status and evidence are already structured and ready.
AI-Powered
Assess risk posture and action items with AI
Use the Docusnap AI Assistant to analyze your recorded risks, vulnerabilities and actions. The analysis gives you an assessment of your current risk posture and highlights where action is needed, instead of leaving the evaluation to manual review.
Instruments
Three instruments for a working ISMS
IT documentation, security and policies all draw from the same data in Docusnap. One shared inventory across all three domains.
Assets straight from the CMDB
Inventoried IT components are available as protection objects in the ISMS. Hardware, software, network devices and their dependencies come directly from existing documentation.
Policies as guided SmartDocs
Policies and security guidelines are created through a guided process instead of starting with a blank Word document. SmartDocs sit in the ISMS right next to risks and assets.
Risk matrices for assessment
Likelihood and impact are assessed visually in a matrix. The view gives a quick overview of risk distribution and prioritizes where action is needed.
Actions
From derivation to effectiveness review
Every action in Docusnap has an owner, a status and a target date. From derivation from a risk through implementation to the effectiveness review, the entire lifecycle remains traceable. In the next management review or audit, the overview shows at a glance which actions are open, in progress or completed.
Frequently asked questions about the ISMS in Docusnap
Does the ISMS cover the requirements of ISO/IEC 27001, NIS2 and BSI IT-Grundschutz?
How does the ISMS module differ from a dedicated GRC tool?
What evaluations does the permissions analysis provide?
How are responsibilities assigned in the ISMS?
Are policies created directly in the ISMS?
Build your ISMS on real data
Try Docusnap and see how risk management, action tracking and permissions analysis work together on a shared data foundation.
Free trial, no commitment



