Asset & risk management depth
ISMS.online
A dynamic risk register with treatment plus 'automated risk assessments and real-time monitoring' is more than a flat list, and the risk-policy-evidence link updating together is welcome. But the evidence never mentions an asset inventory, a documented risk methodology, protection-needs inheritance, or any incident workflow with reporting clocks — a big silence for an ISO 27001 platform, so it sits below the 5 anchor.
verinice
This is a genuine risk backbone: the Grundschutz domain captures target objects, threats, risks and measures, computes automatic protection-needs inheritance, and offers the Basis-, Standard- and Kernabsicherung paths a drafted officer like me can actually follow. The NIS2 domain names the statutory clocks — report after 24 hours, situation report after 72 — and adds supply-chain documentation and TOM capture. I found no public information on risk acceptance with named owners, which is the one piece of the chain the pages leave dark.