News

News and Press Releases

From now on verinice and verinice.PRO version 1.24.1 are available for download in the verinice.SHOP or in the customer repository. The verinice.TEAM provides more than 40 new features, detail changes and bug fixes with verinice 1.24.1. Detailed information can be found in the Release Notes.

Central innovation in verinice 1.24.1 is the referencing of building blocks in the modernized BSI IT-Grundschutz, which is now simplified and visually highlighted. With building block referencing, it is possible to use building blocks already modeled in the information network for several target objects at the same time. This reduces both the effort required for editing and maintaining the modules and the number of modules contained in the information network. In the process, the target objects for which a building block referencing exists are clearly marked.

From this version on, the Windows client is delivered signed. The use of verinice is also supported on a current MacBook with an M1 processor.

Due to security vulnerabilities in older log4j versions, a switch to reload4j is made with verinice 1.24.1.

NOTE: verinice 1.24.1 is the most current version. After an update to verinice 1.24, multiple IDs were displayed in the client behind the names of the objects. This feature, intended for debugging, caused unwanted noise, but no errors in the application and verinice could be used as usual. The problem also did not occur with a new installation - nevertheless, the team provided a new version 1.24.1.

If you need help updating to verinice 1.24.1, do not hesitate to contact us at verinice@remove-this.sernet.de – you can also use the verinice forum for exchanges with the verinice team as well as other users. 


Last week, a vulnerability - now known as Spring4Shell - was discovered in the Spring framework. It is registered as CVE-2022-22965, technical details can be found in this article, among others: https://snyk.io/blog/spring4shell-zero-day-rce-spring-framework-explained/

verinice.PRO is only affected under certain conditions: Only if the verinice-REST-Service is installed on the server. In a standard installation of verinice.PRO, the verinice REST service is generally not included. The verinice single-user version is not affected by this vulnerability at all.

Since the verinice REST service can be affected by the vulnerability under certain circumstances, the verinice team has created a new version of this application. This closes the vulnerability and is available via the verinice GitHub repository: https://github.com/SerNet/verinice-rest-service/releases/tag/0.5. We recommend updating to this new version 0.5 if you have the verinice REST service installed.

Please contact our support if you have further questions or need help.


International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) are working to update the ISO/IEC 2700x family. ISO/IEC 27001:2022 is expected to be published between May and October 2022 – the revised ISO/IEC 27002:2022 has been available since February 15, 2022. There will also be changes for verinice users who operate an ISMS according to ISO 27001 using the open source ISMS tool from SerNet GmbH.

Foreseeable for ISO/IEC 27001:2022 is already: while the management requirements for the ISMS in chapters 4 to 10 offer little that is new, Annex A has been extensively revised with now four chapters and 93 instead of 114 normative controls.

The "ISO 27002:2022 Information security, cybersecurity and privacy protection – Information security controls", published in mid-February 2022, now contains guidelines for the implementation of the controls on organizational, physical, personnel and technical aspects in 4 instead of 14 chapters. The decisive factor here is that no control remains unchanged compared to the previous version. Specifically, one control has been dropped, 56 controls have been combined into 24 controls, 11 controls are new and all others have been reformulated. Also new in Annex A is the consideration of attributes for Control Type, Information Security Properties, Cybersecurity Concepts, Operational Capabilities and Security Domains, Annex B finally contains a mapping of the old to the new controls.

The verinice.TEAM is working on the implementation in verinice. Yet, this cannot be done comprehensively until the certifiable ISO/IEC 27001 is published. After the final release of the new versions, a transition period will apply to bring the ISMS up to date. However, the verinice team recommends that all those who operate an ISMS in accordance with ISO 27001 deal with the updates at an early stage and, if necessary, involve the verinice partners in the migration in a supportive manner.


The Orga Committee has published the agenda for the verinice.XP. The conference for users of the open source ISMS tool will take place on February 23, 2022 - digitally and free of charge. In addition, the verinice team will introduce verinice.veo - the next generation verinice. Tickets for verinice.XP 2022 are available at https://verinicexp.org. The detailed agenda is also presented here

The program at a glance

With "Innovations in the B3S health care in the hospital as well as the starter package § 75c SGB V" Marion Beck (German Hospital Association) opens the conference day.  A practical look at the "Security Management in the hospital" and for this the integration of the open source tools verinice and KIX casts Rico Barth (c.a.p.e IT).

Maximilian Stadler and Marc Drechsler (both Cassini Consulting) deliver the impulse lecture "With holistic planning to organizational resilience".  Frederik von Zedlitz (Cassini Consulting) talks about the "Interplay of confidentiality and information security" and the benefits of verinice for this.

Viktor Rechel (secuvera) will talk about penetration testing as part of an ISMS - basics, relevance and possible approaches. Christian Breitenstrom (UNeedSecurity) addresses "Cloud Compliance in verinice - M365 Compliance Manager" with a focus on the Cloud Computing Compliance Controls Catalogue (C5), which is available as an add-on module for verinice. Horst Pittner (Secianus) takes on the mapping of the iKfz3 procedure in verinice as a solution for representing the enormous security requirements for the registration offices for the operation of the iKfz procedures. The possibilities of an analysis of the IT baseline protection standard with graph databases are shown by Alexander Koderman (verinice team, SerNet). He suggests countering the increasing workload of compliance officers with automation and using new evaluation options and insights for this purpose.

Presenting verinice.veo – the next generation verinice

The verinice.XP is an opportunity to get a first look at verinice.veo. SerNet is working on the second generation of the ISMS tool verinice, combining the technical strengths of the proven ISMS tool with the latest web technology as a software-as-a-service (SaaS) solution. Sirin Torun (SerNet / verinice.TEAM) will present the verinice.veo data protection manager. The DSMS tool for web-based data protection management according to DSGVO will soon be offered as the first product on the new platform for single use in companies and public authorities.

verinice.veo will replace the previous ISMS tool verinice within the next five years. The migration of existing modelling e.g. according to ISO 27001, BSI IT baseline protection or VDA-ISA/TISAX will then enable users to switch directly to the new generation of the ISMS tool. The roadmap for both the existing verinice and verinice.veo will be presented by Michael Flürenbrock.

Workshops on 22.02.

Workshops on data protection and IT baseline protection with verinice are also scheduled for the day before the conference (Tuesday, February 22, 2022). In small groups of participants, they are intended to enable an intensive exchange with expert colleagues and speakers.

The cost of attending one of the full-day workshops is 450 euros. Booking is available through the conference site at verinicexp.org. An up-to-date verinice single-user version will be available for download for active participation in the workshops. Participation is possible independently of verinice.XP.

About the verinice.XP

For years, verinice.XP has been bringing together IT decision-makers, security managers and data protection officers from companies, institutions and public authorities. They are all united by the use of verinice for the management of information security or data protection.


ATTENTION: The release date of verinice 1.24 had to be moved to mid-May.

The verinice team plans the release of version 1.24 for the end of April 2022. The feature freeze will occur in early April to ensure an extensive testing period. Users can discuss verinice 1.24 as well as other upcoming versions with the team in the community area. In addition, they can suggest new features there themselves or debate details about features already suggested.

We are happy to assist you with an update to verinice 1.24 as part of a support contract or a support budget. To do so, please contact us early to arrange an appointment.

Independent of the release, the new IT baseline protection compendium of the BSI will also be made available for verinice directly after its publication. The expected timeframe for this is the beginning of February 2022.

At this year's verinice.XP (February 23 & 24, 2022), which will also take place digitally, the verinice team will present the first version of verinice.veo


Search News

Press contact:

Claudia Krell
presse@remove-this.sernet.de

Archive:

Deutsch English Lingua italiana Český jazyk
© SerNet GmbH, 2022