Business partner for structure and demonstration

Normity as an ISMS tool within risk analysis and improvement projects

Kynexis Information Security uses Normity to link documents, risks, measures, evidence, findings, actions and ownership structuredly. This will provide a workable basis for monitoring and demonstrable control.

Normity logo

Supporting software for risk analysis, ISMS, documentation, evidence and follow-up.

Visit normity. en

Why Kynexis works with Normity

Monitoring research findings manageable

A report is pointing in the direction. Sustainable improvement also requires a place where risks, decisions, evidence, actions and responsible persons are kept in a coherent manner.

Normity offers that structure. Kynexis Information Security adds the substantive assessment: what risks are relevant, what measures are appropriate to the organisation, what evidence is convincing and what improvements should be priorityd? For example, software and advice together support the board-level and operational management.

ISMS tools in practice

What we bring together in Normity

The establishment follows the assignment and the organisational context. The components together form a traceable file for risks, control and improvement.

Context and assets

Critical processes, information, applications, suppliers, owners and interdependencies.

Risk analysis

Threats, vulnerabilities, scenarios, opportunity, impact, existing measures and risk appetite.

Measures and evidence

Policies, procedures, controls, records and a well-documented evidence register for demonstrability.

Improvement and ownership

Findings, treatment choices, actions, controllers, deadlines, progress and periodic review.

Applications

Risk analysis support, ISO 27001, ISMS and NIS2

Normity helps to capture and follow the approach chosen. Kynexis Information Security ensures that content, priority and decision making fit the organisation.

How we work

Content guidance and software in one logical route

The setup grows with the engagement. We start with the decision that needs to be made and use only the components that add value for the organisation.

  1. 01

    Determining context

    Focusing objective, scope, critical processes, standards, legal context and information needs.

  2. 02

    Research and structuring

    Coherence assessment of documents, interviews, risks, measures, findings and available evidence.

  3. 03

    Prioritizing and investing

    Linking risks and improvement measures to decisions, owners, deadlines and desired results.

  4. 04

    Follow-up and reporting

    Update and make administratively negotiable progress, evidence and residual risks.

Clear roles

Normity offers structure. Kynexis Information Security brings content and direction.

NORMITY

Support platform

  • central commitment and relationships;
  • risk register and threat models;
  • document and evidence management;
  • actions, owners and progress;
  • reporting and monitoring.
View the software of Normity .
KYNEXIS INFORMATIEBEVEILIGING

Analysis, advice and guidance

  • define scope and organisational context;
  • assess the substance of the risks and measures;
  • test evidence and detectable effect;
  • advise priorities and risk management;
  • Manage, manage and manage.
Discuss your question with Kynexis Information Security →

Frequently Asked Questions

Normity, ISMS tools and risk analysis

Is Normity an ISMS tool?

Normity supports management systems, standards, risk analysis, documentation, actions and evidence. Kynexis Information Security uses these capabilities to help organise and demonstrate an ISMS for ISO 27001 or a broader approach to information security.

What does Kynexis Information Security use Normity for in a risk analysis?

Kynexis Information Security can connect business context, processes, business resources, threats, risks, existing measures, evidence, risk treatment, owners and follow-up actions. This creates a traceable risk file instead of a snapshot.

Does Normity itself provide an NIS2 or ISO 27001 certification?

Normity supports the design, documentation and follow-up. Kynexis Information Security provides the substantive analysis and guidance. An independent certification body shall assess any ISO 27001 certification; NIS2 requires appropriate and demonstrably effective measures within its own organisational context.

Is Normity necessary for every assignment?

Kynexis Information Security, together with the client, determines which method suits the demand, maturity and existing systems. Normity is used when structural commitment, cooperation, evidence and follow-up offer clear added value.

Wouter Parent

An ISMS tool brings structure, but does not make decisions. The quality remains dependent on a sharp risk analysis, realistic treatment choices and owners who can be seen to follow.

Current
WebinarFree webinars on NIS2, cyber risk management and oversight

Choose a live session for the board, executive team, supervisory board or board of trustees and register directly.

View webinars and dates