Context and assets
Critical processes, information, applications, suppliers, owners and interdependencies.

Business partner for structure and demonstration
Kynexis Information Security uses Normity to link documents, risks, measures, evidence, findings, actions and ownership structuredly. This will provide a workable basis for monitoring and demonstrable control.

Supporting software for risk analysis, ISMS, documentation, evidence and follow-up.
Visit normity. enWhy Kynexis works with Normity
A report is pointing in the direction. Sustainable improvement also requires a place where risks, decisions, evidence, actions and responsible persons are kept in a coherent manner.
Normity offers that structure. Kynexis Information Security adds the substantive assessment: what risks are relevant, what measures are appropriate to the organisation, what evidence is convincing and what improvements should be priorityd? For example, software and advice together support the board-level and operational management.
ISMS tools in practice
The establishment follows the assignment and the organisational context. The components together form a traceable file for risks, control and improvement.
Critical processes, information, applications, suppliers, owners and interdependencies.
Threats, vulnerabilities, scenarios, opportunity, impact, existing measures and risk appetite.
Policies, procedures, controls, records and a well-documented evidence register for demonstrability.
Findings, treatment choices, actions, controllers, deadlines, progress and periodic review.
Applications
Normity helps to capture and follow the approach chosen. Kynexis Information Security ensures that content, priority and decision making fit the organisation.
Assess risk scenarios, define treatment choices and organise ownership.
View risk analysis →ISO 27001 SOFTWARE AND GUIDANCEConnecting standards, processes, documents, risks, measures and evidence.
View ISO 27001 guidance →NIS2 AND THE DUTCH CYBERSECURITY ACTPrioritize and follow board-level, organisational and technical improvement points.
View NIS2 GAP Analysis →GOVERNANCE AND ASSURANCEBring risks, controls, evidence, actions and management reporting together in a recognisable cycle.
View internal control →How we work
The setup grows with the engagement. We start with the decision that needs to be made and use only the components that add value for the organisation.
Focusing objective, scope, critical processes, standards, legal context and information needs.
Coherence assessment of documents, interviews, risks, measures, findings and available evidence.
Linking risks and improvement measures to decisions, owners, deadlines and desired results.
Update and make administratively negotiable progress, evidence and residual risks.
Clear roles
Frequently Asked Questions
Normity supports management systems, standards, risk analysis, documentation, actions and evidence. Kynexis Information Security uses these capabilities to help organise and demonstrate an ISMS for ISO 27001 or a broader approach to information security.
Kynexis Information Security can connect business context, processes, business resources, threats, risks, existing measures, evidence, risk treatment, owners and follow-up actions. This creates a traceable risk file instead of a snapshot.
Normity supports the design, documentation and follow-up. Kynexis Information Security provides the substantive analysis and guidance. An independent certification body shall assess any ISO 27001 certification; NIS2 requires appropriate and demonstrably effective measures within its own organisational context.
Kynexis Information Security, together with the client, determines which method suits the demand, maturity and existing systems. Normity is used when structural commitment, cooperation, evidence and follow-up offer clear added value.

An ISMS tool brings structure, but does not make decisions. The quality remains dependent on a sharp risk analysis, realistic treatment choices and owners who can be seen to follow.