News
verinice

Easy Migration to the New Generation of verinice

The VNA Importer is here. Existing verinice customers can now migrate their data themselves to verinice.cloud or verinice.onprem. The importer is available as a web service. A detailed documentation is also available.

It is based on the VNA archive format, which all verinice versions export. And it’s that simple: Select a file, enter the URL of the target instance and your login credentials—then start the import. The importer creates a new unit in the target environment and copies the content there—the source data remains unchanged. Multiple information sets can be imported into a single unit, and the process can be repeated as often as needed.

All target objects are transferred, including their links, building blocks, requirements, and elementary threats, as well as the protection requirement values for confidentiality, integrity, and availability, and the risk assessment.

Implementation Levels
The first stage covers the “Modernized IT-Grundschutz” perspective and maps it to the “IT-Grundschutz” and “Data Protection” domains. This is followed by migration from the ISO/ISM perspective to the ISO 27001 domains (including data protection) and the transfer of BCM data to BSI 200-4 or ISO 22301; the dates are listed in the Roadmap.

Before Export: Check Modeling
In the new generation of verinice, the implementation of a requirement is no longer documented in the requirement itself, but rather in the link to the target object. Each building block and each requirement now exists only once and is linked to multiple target objects. This deduplication saves a considerable amount of effort in day-to-day use, but requires clean source data. You can find the exact procedure for this in the documentation.

For testing purposes, the importer offers a “Dry Run”: The import runs through the process without writing any data and reports errors in advance. A “Strict Run” performs an even more rigorous check. It’s worth running both before performing a production import.

verinice.onprem without an Internet connection
For air-gapped target environments without access to the web service, the VNA Importer is available as a Java client. Please contact support@remove-this.verinice.com for this.

Contact us
Contact