The latest version of verinice is now available. With V 1.10 users have access to the IT Baseline Protection Catalogs in English and can use the new edition of the VDA IS-Assessment in version 2.x. Exclusive new features for the server version verinice.PRO are single-sign-on with Active Directory and importing users from the AD into the IT Baseline view as well as the optimization of the task view.
Important note for the update: Due to the necessary data migration, thefirst launch of verinice clients after updating may take a bit longerthan usual. Don’t panic. For more information, see the section "Display of file size in the File View". Please also note the general indicationsregarding the update and the release notes.
The new features at a glance:
English IT Baseline Protection Catalogs
The full text of the IT Baseline Protection Catalogs published by the German Federal Office for Information Security (BSI) is now available in English. Especially international teams benefit from this, simplifyingthe work with the IT Baseline Protection significantly.
However, users of the native ISO 27001:2013 can profit from the comprehensive catalog of risks and controls as well: during risk assessment and risk treatment the Baseline Protection Catalogs can be used as a comprehensive database, especially on specific topics like Windows or SAP.
All risks can be used as scenarios in an individual risk assessment. Simply drag-and-drop the desired risks or whole modules into the risk model. The catalogs, containing more than 1,500 Baseline Protection controls, will proof to be useful during risk treatment. As specific controls, they supplement the generic requirements of ISO / IEC 27002:2013. The controls are easily dragged-and-dropped into the ISM-risk model.
The English IT Baseline Protection Catalogs correspond to the 13th catalog update version from the BSI.
Update on VDA ISA 2.x
verinice V 1.10 fully supports the new edition of the IS-Assessment catalog published by the German Association of the Automotive Industry (VDA) in version 2.x. Apart from the actual catalog, the method of calculating the averages and the "Total Security Figure" have been adjusted. The issued report provides the radar chart indicating the level of maturity reached and the target level of maturity for each chapter, taking into account all the questions marked "NA".
Users of verinice are absolutely compliant with the VDA standard. Moreover a consolidator allows to import assessment results originating from theVDA 1.x standard. Shifts of controls etc. are taken into account properly.
Display of file size in the file view
The file view now reveals the file size of each attachment. This accelerates, for example, the inevitable clean up of a growing database.
Note: After updating to V 1.10 the file size information is updated in the database. The update will be triggered at the first connection of a verinice client to the database. Depending on the number of attachments this can take from a few seconds up to several minutes to complete. We therefore recommend to immediately perform a client-start after the server update, so the update is complete before the first regular user logs in. The migration is executed only once.
Exclusive features of verinice.PRO
Single-Sign-On with Active Directory
On Windows-clients verinice.PRO now supports Single-Sign-On: registered users are automatically logged in to verinice.PRO. Re-entering the username and password is not required.
The previous registration mechanism with renewed user and password input is still available as an alternative, e.g. if you want to work in verinice with another user as the one logged in into Windows.
Import of individuals from AD in the baseline protection view
When running an AD import it is now possible to select whether the imported persons and accounts are created in the ISM or in the Baseline Protection model.
Optimization of the task view
The task view has been improved: Tasks load faster and a detailed search allows you to find specific tasks. Tasks can be sorted by group, editor, process, task type, start and end date.
Improvements and bug fixes
Minor improvements and a variety of fixed bugs in various places roundoff V 1.10. Some worth mentioning are:
- In the web front-end for tasks the full text of Baseline Protection Controls can now be viewed. This makes it easier to delegate the basic security check as well as control implementation.
- The local report repository on the verinice client now works as intended.
- The allocation of modules, users and target types when using the GSTOOL import have been corrected.
- Inheriting custom icons to child objects can now be switched on or off.
- When moving objects it can be selected if the permissions of the destination folder should be applied to the moved object.
- Double-clicking an attachment in the file view now selects the associated object in the tree view.
- The standard account view display was changed to: "Last name, firstname [account]"
- When displaying account groups, the right hand display does not show a total list of all accounts as before, but only those who are not included in the selected group. This facilitates the search for non-associated accounts.
- The customization file ("SNCA.xml") will no longer be moved during the update process but will continue to operate as is. Attention: Please continue to follow the update instructions for dealing with configuration files!