News and information about verinice.

Learn everything that is important

Version 1.26 of verinice and verinice.PRO is now available for download from the verinice.SHOP or from the Customer Repository. The verinice.TEAM provides new features, detail changes and bug fixes with this release. Support for the new ISO/IEC 27001:2022 is the main new highlight. Details are available in the full Release Notes.

The team plans to release the new verinice risk catalog with the relevant content of the ISO 27001 family shortly. In parallel, the customization of the risk analysis in the ISM/ISO perspective has been simplified. In the associated report templates, the risk matrices for confidentiality, integrity and availability can now be customized.

As part of the product maintenance, verinice 1.26 also updates the Rich Client Platform (RCP) and the Java Development Kits (JDK) in addition to numerous detail improvements and bug fixes.

In addition to the new edition of the risk catalog, the data protection module with IT-Grundschutz-Kompendium Edition 2023 should also be available soon.

In addition to the development of the classic verinice, SerNet is working intensively on the new platform verinice.veo, which has been launched with the first product verinice DSMS. Learn more about the fully web-based data protection manager and test our next generation tool for one month free of charge: find out more at or contact our sales team directly at

[Translate to English:] IT-Governance-Artikel

The verinice team is not only working on the further development of the professional application, but is also constantly opening up new areas. Among other things, Alexander Koderman, developer and verinice inventor from the very beginning, has dealt intensively with graph databases. Together with Mirko Prehn, he published the article "The Use of Graph Databases in Compliance Automation" in issue 36/December 2022 of IT-Governance magazine, the professional journal of the ISACA Germany Chapter e.V.. We make the article available here as a special PDF edition (read complete article).

From the content: Modern graph databases are perfectly suited to solve typical challenges in compliance management. They can be perfectly combined with current developments in machine-readable formats such as the recently completed OSCAL standard. However, some challenges remain.

At the GraphConnect 2022 conference, Koderman also presented "Cybersecurity Automation with OSCAL and Neo4J." The presentation was recorded and can be viewed on YouTube:

Play YouTube-Video "verinice.veo und ChatGPT"

The verinice.XP 2023 was the meeting point for users of the ISMS tool verinice at the end of February. A special highlight was a report by Alexander Koderman (verinice.TEAM / SerNet GmbH) directly from the verinice lab: the integration of ChatGPT into the new platform verinice.veo using the veo copilot as a browser plugin. Koderman has published the associated code on GitHub:

The entire talk (in German) can be seen at In it, Koderman also immediately cleared up a common misconception when dealing with language models, which can be solved with the necessary background knowledge and the right query. 

Koderman highlights the tremendous progress of language models that everyone has seen in recent weeks and months. Not only can they now solve puzzles faster than humans can even read them. ChatGPT and co. are also now processing the concepts behind them. The impact of AI on information security management is correspondingly far-reaching, he says: "The way we analyze cybersecurity risks, implement measures and ensure compliance will change dramatically." The use of AI-powered tools in information security management has the potential to significantly improve the efficiency and effectiveness of the work, he said.

ChatGPT as copilot

Koderman also sees a lot of potential for verinice: "The ongoing development and expansion of language models presents us as tool developers with challenges and opportunities: how can we incorporate natural language interfaces into traditional user interfaces? In the coming months, we will answer these questions and add exciting new features to verinice.veo."

A first answer is already available as an experiment: The veo copilot as a browser plugin. This can be used to test and play in the web-based verinice DSMS, which is available now. In his presentation, Koderman not only demonstrates how this works, but also takes this opportunity to give a little insight into the latest generation verinice. Meanwhile, the copilot also uses the current language model behind ChatGPT, which is now available via the OpenAI API.

More recordings of verinice.XP 2023 will be gradually published on the verinice YouTube channel:

[Translate to English:] Zu den Videos zu BCM in verinice

verinice enables the work on an Emergency Management System resp. Business Continuity Management System (BCMS) according to ISO 22301 or BSI Standard 200-4. For the BSI perspective, an exemplary structure is now available, for the ISM perspective an exemplary organization: The mapping of BCM-relevant aspects makes users familiar with the innovations around the topic of BCM with verinice and facilitates the start. Both are available free of charge via the verinice.SHOP.

In addition to mapping the ISMS, the BCM extensions in verinice also allow establishing a BCMS (learn more at verinice supports users throughout the entire PDCA cycle. Videos are also available for each perspective in the YouTube channel of the verinice team, showing step-by-step how to proceed.

You have further questions about BCM with verinice? Feel free to use the verinice forum or contact our sales team.

This is what the BCM sample data offers:

The data comes in the form of a .VNA file for import into verinice version 1.25 and higher. Included is an exemplary structure or organization with sample data for a BCMS with the following scope:

  1. Initiating, designing and planning the BCM/BCMS

    • Determining the boundaries and applicability of the BCMS

    • Determining the scope of application of the BCMS

    • Analysis of extended framework conditions / context of the organization (eg stakeholder analysis)

    • Definition of the BCM structure organization

    • Allocate and ensure responsibilities for relevant roles

    • Documentation of BC relevant documents

  2. In the implementation of an appropriate safeguarding of business processes

    • Conducting business impact analysis (BIA)

    • Preparation of a target/actual comparison

    • Risk management with risk analysis according to BSI standard 200-3 or ISO 27005

    • Manage business continuity strategies / solutions

  3. In performance review and reporting

    • BCM reporting: evaluation of BIA parameters (MTPD, RTO, RPO) or your critical business processes

    • Capture and evaluation of BCM-relevant key figures

  4. In correcting and improving the BCMS

    • Management of derived actions, e.g. corrective and improvement actions

    • Creation of a BCM action plan


Search News

Press contact:

Claudia Krell


Deutsch English Lingua italiana Český jazyk
© SerNet GmbH, 2023