ISMS Audits and BSI Catalogs
Conduct professional audits based on BSI IT-Grundschutz, CISIS12, and VdA ISA – with ready-to-use catalogs and no lead time. Use the predefined content or build your own catalogs from requirements, applicability and threats. You steer ISO 27001 standard compliance in parallel via ready-to-use requirement catalogs with a Statement of Applicability and a heatmap cockpit. Document degrees of fulfillment and evidence centrally and prepare specifically for internal and external certification audits.
SUPPORTED STANDARDS
Audits based on BSI IT-Grundschutz, CISIS12, and VdA ISA
preeco includes ready-to-use audit catalogs based on the German-recognized standards [BSI IT-Grundschutz](/en/regulations-bsi-it-grundschutz), [CISIS12](/en/regulations-cisis12), and [VdA ISA](/en/regulations-vda-isa) (optional and paid) – usable right away, with no waiting time. Document degrees of fulfillment for each requirement, assign measures, and prepare for external certification audits.
- BSI IT-Grundschutz: ready-to-use audit catalog (optional and paid)
- CISIS12: ready-to-use audit catalog (optional and paid)
- VdA ISA: ready-to-use audit catalog (optional and paid) – the assessment basis for TISAX in the automotive sector; results exportable as PDF or DOCX for your TISAX assessment
- ISO/IEC 27001: ready-to-use requirement catalog with heatmap cockpit, maturity level and Statement of Applicability (SoA) for steering standard compliance
- SiKoSH: own requirement catalog for municipal information security
- Freely define your own audit catalogs – e.g. to capture ISO 27001 requirements or your organization's own specifications, for individual information security reviews in your organization
AUDIT FEATURES
Structured execution and measure assignment
Systematically work through all requirements, document degrees of fulfillment, and capture evidence. Evidence and measures recorded once can be reused across audits through linking. In case of deviations, assign measures directly with responsible persons and deadlines.
- Hierarchically structured audit objects with audit object type and applicability
- Checklists with degree of fulfillment, evidence, and measures
- Measure assignment directly from within the audit
- Compose custom audit catalogs from requirements, applicability and threats
- Document interviewed persons per requirement
- Graphical audit progress including aggregation on superordinate audit objects
- Reuse evidence and measures across multiple audits through linking
- Export as report for management and certification bodies
- Download an individual requirement as a document (PDF and DOCX) including assessment, evidence, linked documents, classifications to other standards and the review history – cover sheet and layout customizable via the document settings
- Dedicated user right for a personal worklist: a user group sees exclusively the requirements assigned to it along with associated tasks, evidence and deadlines – without insight into the entire catalog
- Linking with assets, risk analyses, and ISMS documentation
PROGRESS & VERSIONING
Progress tracking and traceable versioning
The dashboard shows the status of all audits at any time – open items and upcoming repeat audits at a glance. All audit results are stored with version control, so changes are always traceable.
- Dashboard with current status of all ongoing audits
- Follow-ups for scheduled repeat audits
- Complete versioning of all audit results
- Audit-proof documentation for accountability requirements
- Key figures and regular snapshots of the development of the degree of fulfillment over time
Terms on this page, briefly explained
Professionalize your ISMS now
In a personal consultation, we'll show you how preeco | information security simplifies your security management.