News

News and Press Releases

From now on verinice and verinice.PRO version 1.24.1 are available for download in the verinice.SHOP or in the customer repository. The verinice.TEAM provides more than 40 new features, detail changes and bug fixes with verinice 1.24.1. Detailed information can be found in the Release Notes.

Central innovation in verinice 1.24.1 is the referencing of building blocks in the modernized BSI IT-Grundschutz, which is now simplified and visually highlighted. With building block referencing, it is possible to use building blocks already modeled in the information network for several target objects at the same time. This reduces both the effort required for editing and maintaining the modules and the number of modules contained in the information network. In the process, the target objects for which a building block referencing exists are clearly marked.

From this version on, the Windows client is delivered signed. The use of verinice is also supported on a current MacBook with an M1 processor.

Due to security vulnerabilities in older log4j versions, a switch to reload4j is made with verinice 1.24.1.

NOTE: verinice 1.24.1 is the most current version. After an update to verinice 1.24, multiple IDs were displayed in the client behind the names of the objects. This feature, intended for debugging, caused unwanted noise, but no errors in the application and verinice could be used as usual. The problem also did not occur with a new installation - nevertheless, the team provided a new version 1.24.1.

If you need help updating to verinice 1.24.1, do not hesitate to contact us at verinice@remove-this.sernet.de – you can also use the verinice forum for exchanges with the verinice team as well as other users. 


Last week, a vulnerability - now known as Spring4Shell - was discovered in the Spring framework. It is registered as CVE-2022-22965, technical details can be found in this article, among others: https://snyk.io/blog/spring4shell-zero-day-rce-spring-framework-explained/

verinice.PRO is only affected under certain conditions: Only if the verinice-REST-Service is installed on the server. In a standard installation of verinice.PRO, the verinice REST service is generally not included. The verinice single-user version is not affected by this vulnerability at all.

Since the verinice REST service can be affected by the vulnerability under certain circumstances, the verinice team has created a new version of this application. This closes the vulnerability and is available via the verinice GitHub repository: https://github.com/SerNet/verinice-rest-service/releases/tag/0.5. We recommend updating to this new version 0.5 if you have the verinice REST service installed.

Please contact our support if you have further questions or need help.


International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) are working to update the ISO/IEC 2700x family. ISO/IEC 27001:2022 is expected to be published between May and October 2022 – the revised ISO/IEC 27002:2022 has been available since February 15, 2022. There will also be changes for verinice users who operate an ISMS according to ISO 27001 using the open source ISMS tool from SerNet GmbH.

Foreseeable for ISO/IEC 27001:2022 is already: while the management requirements for the ISMS in chapters 4 to 10 offer little that is new, Annex A has been extensively revised with now four chapters and 93 instead of 114 normative controls.

The "ISO 27002:2022 Information security, cybersecurity and privacy protection – Information security controls", published in mid-February 2022, now contains guidelines for the implementation of the controls on organizational, physical, personnel and technical aspects in 4 instead of 14 chapters. The decisive factor here is that no control remains unchanged compared to the previous version. Specifically, one control has been dropped, 56 controls have been combined into 24 controls, 11 controls are new and all others have been reformulated. Also new in Annex A is the consideration of attributes for Control Type, Information Security Properties, Cybersecurity Concepts, Operational Capabilities and Security Domains, Annex B finally contains a mapping of the old to the new controls.

The verinice.TEAM is working on the implementation in verinice. Yet, this cannot be done comprehensively until the certifiable ISO/IEC 27001 is published. After the final release of the new versions, a transition period will apply to bring the ISMS up to date. However, the verinice team recommends that all those who operate an ISMS in accordance with ISO 27001 deal with the updates at an early stage and, if necessary, involve the verinice partners in the migration in a supportive manner.


The Orga Committee has published the agenda for the verinice.XP. The conference for users of the open source ISMS tool will take place on February 23, 2022 - digitally and free of charge. In addition, the verinice team will introduce verinice.veo - the next generation verinice. Tickets for verinice.XP 2022 are available at https://verinicexp.org. The detailed agenda is also presented here

The program at a glance

With "Innovations in the B3S health care in the hospital as well as the starter package § 75c SGB V" Marion Beck (German Hospital Association) opens the conference day.  A practical look at the "Security Management in the hospital" and for this the integration of the open source tools verinice and KIX casts Rico Barth (c.a.p.e IT).

Maximilian Stadler and Marc Drechsler (both Cassini Consulting) deliver the impulse lecture "With holistic planning to organizational resilience".  Frederik von Zedlitz (Cassini Consulting) talks about the "Interplay of confidentiality and information security" and the benefits of verinice for this.

Viktor Rechel (secuvera) will talk about penetration testing as part of an ISMS - basics, relevance and possible approaches. Christian Breitenstrom (UNeedSecurity) addresses "Cloud Compliance in verinice - M365 Compliance Manager" with a focus on the Cloud Computing Compliance Controls Catalogue (C5), which is available as an add-on module for verinice. Horst Pittner (Secianus) takes on the mapping of the iKfz3 procedure in verinice as a solution for representing the enormous security requirements for the registration offices for the operation of the iKfz procedures. The possibilities of an analysis of the IT baseline protection standard with graph databases are shown by Alexander Koderman (verinice team, SerNet). He suggests countering the increasing workload of compliance officers with automation and using new evaluation options and insights for this purpose.

Presenting verinice.veo – the next generation verinice

The verinice.XP is an opportunity to get a first look at verinice.veo. SerNet is working on the second generation of the ISMS tool verinice, combining the technical strengths of the proven ISMS tool with the latest web technology as a software-as-a-service (SaaS) solution. Sirin Torun (SerNet / verinice.TEAM) will present the verinice.veo data protection manager. The DSMS tool for web-based data protection management according to DSGVO will soon be offered as the first product on the new platform for single use in companies and public authorities.

verinice.veo will replace the previous ISMS tool verinice within the next five years. The migration of existing modelling e.g. according to ISO 27001, BSI IT baseline protection or VDA-ISA/TISAX will then enable users to switch directly to the new generation of the ISMS tool. The roadmap for both the existing verinice and verinice.veo will be presented by Michael Flürenbrock.

Workshops on 22.02.

Workshops on data protection and IT baseline protection with verinice are also scheduled for the day before the conference (Tuesday, February 22, 2022). In small groups of participants, they are intended to enable an intensive exchange with expert colleagues and speakers.

The cost of attending one of the full-day workshops is 450 euros. Booking is available through the conference site at verinicexp.org. An up-to-date verinice single-user version will be available for download for active participation in the workshops. Participation is possible independently of verinice.XP.

About the verinice.XP

For years, verinice.XP has been bringing together IT decision-makers, security managers and data protection officers from companies, institutions and public authorities. They are all united by the use of verinice for the management of information security or data protection.


ATTENTION: The release date of verinice 1.24 had to be moved to mid-May.

The verinice team plans the release of version 1.24 for the end of April 2022. The feature freeze will occur in early April to ensure an extensive testing period. Users can discuss verinice 1.24 as well as other upcoming versions with the team in the community area. In addition, they can suggest new features there themselves or debate details about features already suggested.

We are happy to assist you with an update to verinice 1.24 as part of a support contract or a support budget. To do so, please contact us early to arrange an appointment.

Independent of the release, the new IT baseline protection compendium of the BSI will also be made available for verinice directly after its publication. The expected timeframe for this is the beginning of February 2022.

At this year's verinice.XP (February 23 & 24, 2022), which will also take place digitally, the verinice team will present the first version of verinice.veo


[Translate to English:] verinice.XP

Due to the current Corona developments, the organising team has decided to hold the verinice.XP 2022 as an online event. Participation in the digital conference on 23 & 24 February 2022 is free of charge. Registration is possible at https://verinicexp.org . The programme will be published at the end of 2021.

Presentation proposals can also be submitted until 17 December at https://verinicexp.org or by email to cfp@remove-this.verinicexp.org.

Workshops on various verinice topics are also planned for the day before the conference (Tuesday, 22 February 2022). We will inform you about the workshop programme shortly. Participation is possible independently of verinice.XP.


Last week, a critical vulnerability in the widely used logging library log4j 2 became known. The log4j versions included in the verinice.PRO server are not affected by the vulnerability!

The vulnerability is described in this article, among others: Log4Shell: RCE 0-day exploit found in log4j 2, a popular Java logging package and has the CVS number CVE-2021-44228 erhalten.

For more information, see the article in our verinice forum: https://forum.verinice.com/t/verinice-nicht-betroffen-von-log4j-schwachstelle/

However, on a verinice.PRO system there may be other Java applications in Tomcat that have not been installed by the verinice team. Since these applications may contain affected log4j versions, the team recommends including a parameter in the Tomcat configuration that prevents exploitation of the vulnerability in other applications. Again, see our forum post for details: https://forum.verinice.com/t/verinice-nicht-betroffen-von-log4j-schwachstelle/

Feel free to contact our team if you have any further questions.


[Translate to English:] verinice.XP

Update (December 15th, 2021): Due to the current Corona developments, the organising team has decided to hold the verinice.XP 2022 as an online event. Participation in the digital conference is free of charge. 

The next verinice.XP will take place from February 22 & 23, 2022 – again on site in Berlin at the Radisson Blu Hotel. Organizer SerNet is looking forward to the direct exchange and meeting of the verinice community.

Early Bird tickets at a price of 399 euros are already available on the conference page at https://verinicexp.org . The program will be published in late 2021.

In addition, paper proposals can be submitted now at https://verinicexp.org or by email to cfp@remove-this.verinicexp.org. The verinice.XP team and the program committee will review the submissions - case studies on the use of verinice are especially sought after presentation topics.

Workshops

Workshops on various verinice topics are again planned for February 22, 2022. In small groups of participants, they are intended to enable intensive exchange with expert colleagues and speakers. We will publish the workshop program shortly. Participation is possible independently of verinice.XP.

About verinice.XP

For years, verinice.XP has been bringing together IT decision-makers, security managers and data protection officers from companies, institutions and public authorities. They are all united by their use of verinice  for information security management or data protection management. A social event is expected to take place on the evening of February 22, 2021 at the conference hotel. About the details - especially taking into account the then valid Corona requirements - we will inform them yet.

.


Version 1.23.1 of verinice is now available for download in the verinice.SHOP.

This update for verinice fixes an error when copying objects. In the single-user version of verinice 1.22.2 and 1.23, the function "Copy with links" could not be executed. Calling up the function is possible again in version 1.23.1.

verinice.PRO was not affected by the error. In the operating mode "Server", the function "Copy with links" can also be executed without errors in older versions. Therefore, no new verinice.PRO packages for 1.23.1 are published in the customer repository. On the server, the packages for 1.23.0 can still be used.

Please refer to the detailed release notes of version 1.23.x. for all further information.


verinice 1.23 Release

From now on verinice and verinice.PRO version 1.23 are available for  download in verinice.SHOP or in customer repository respectively. The verinice.TEAM delivers with verinice 1.23 more than 30 new features, detail changes and bug fixes. These are described in detail in the release notes.

Among other things, verinice 1.23 now uses Java 11, and the Java Runtime Environment (JRE) from Adoptium (formerly AdoptOpenJDK) shipped with the client has been updated to the latest version. For this, update notes are listed in the release notes and must be followed.

To support newer operating systems, the RCP framework has been updated to version 2021-06 (4.20). verinice thus offers better support for the macOS Big Sur operating system in particular.

If you have any questions or need help with the update, feel free to contact us - including by email at verinice@remove-this.sernet.de. You are also welcome to exchange ideas with other users and the verinice team in the Forum (mainly German).

 


Search News

Press contact:

Claudia Krell
presse@remove-this.sernet.de

Archive:

Deutsch English Lingua italiana Český jazyk
© SerNet GmbH, 2022