kombine.work

Modules

Seventeen modules. Nine are always on because the record does not make sense without them, and eight are switched on per company in Settings. Everything is included in the price: a module that is off is off because you do not want it yet, not because of your plan.

Each one is a tab in the application, with its own permissions. A role can be granted read, write or admin on any module individually, so an auditor can be given the whole record without being able to change a line of it.

CMDB and assets

Asset register, vulnerabilities, software and ICT providers. One record per thing: a server that appears in your cloud, your EDR, your scanner and your directory is one asset here, not four rows to reconcile. Always on.

Risk register

Risk registers, scoring methodology and treatment plans. Findings from the connected systems can open a risk directly, so the register reflects what is actually happening rather than what was discussed at the last review. Always on.

Controls and standards

NIS2, DORA and ISO control catalogues and scoring. Select the standards that apply to you and each control carries the sources that satisfied it and the moment each last reported. Always on.

Service requests

Requests, incidents and change requests with SLA tracking. Work that comes out of a finding gets an owner and a deadline rather than a mention in a meeting. Always on.

Compliance calendar

Recurring compliance tasks and their due dates, with the responsible person on each. The things that have to happen quarterly whether or not anyone remembers. Always on.

Non-conformances

Audit findings register with corrective actions. Separate from misconfigurations on purpose: a non-conformance is something an audit raised, and it closes when the corrective action is done and evidenced. Always on.

Documents

ISMS policies and procedures with control mapping, so a policy is linked to the controls it satisfies rather than living in a folder nobody opens between audits. Always on.

Reports

Report builder, saved templates and scheduled exports. The evidence pack an auditor asks for, generated from the live record instead of assembled by hand. Always on.

KPI

Metric targets and performance tracking, with periods that close. Thirty days after a period ends its assessment becomes read-only, so evaluating this quarter cannot quietly rewrite the last one. Always on.

Third party risk (TPRM)

Vendor evaluations, questionnaires and recurring reviews. Suppliers hold contracts, review dates and a criticality, and a questionnaire can be sent to a vendor who fills it in without an account. This is also where the register of ICT third party arrangements lives. Optional.

Products

A business capability lens over the CMDB. Tag assets and people with a product, get a per-product risk score, owners and a portfolio view, so a technical finding can be expressed as which part of the business it threatens. Optional.

Consequence graph

Traces which DORA and NIS2 regulated functions a compromise can reach, and the obligations that come with them. Answers the question a board asks after an incident, which is not what broke but what it was connected to. Optional.

Learning

Training packages, assignments and completion tracking, with a certificate at the end. Awareness training is a requirement in its own right under both NIS2 and the Lithuanian requirements. Optional.

Security

Ingests EDR and XDR alerts from Microsoft Defender and Wazuh, filed against the asset they concern rather than sitting in a separate console. Optional.

Threat intelligence

Watches security feeds, including CISA KEV, the NVD and custom RSS, for advisories affecting the products you actually run. A watchlist built from your own asset register rather than a newsletter. Optional.

Continuous control monitoring

Automated checks that read your synced posture data and flag drift against your control scores. This is what makes a control change state on its own when a setting moves, rather than at the next review. Optional.

Configuration posture

Snapshots your Microsoft 365 configuration, across Entra, Teams, Exchange and Purview, for periodic review with change detection. A tenant setting that changed in March is visible in March. Optional.