Codename: Mal de Plata
Release date: May & July 2023
Version 1.26 / 1.26.1 of verinice and verinice.PRO is now available for download in the verinice.SHOP and the customer repository.
With verinice 1.26 the verinice team provides new features, detail changes and bug fixes.
The most important new feature is the support for the new ISO/IEC 27001:2022 in verinice 1.26. It is planned to release the new verinice risk catalog with the relevant contents of the ISO 27001 family soon. In parallel, the adaptation of the risk analysis in the ISM/ISO perspective was simplified; in the associated report templates, the risk matrices for confidentiality, integrity and availability can now be adapted.
In the context of product maintenance, the RCP development environment and the JDK have been updated in verinice 1.26 in addition to numerous detail improvements and bug fixes.
verinice 1.26.1 additionally fixed two bugs:
- Corrected the signing of verinice packages to SHA-256, as Microsoft Defender warnings were occasionally reported during installation on Windows.
- The handling of Unicode encoding has been improved to prevent a theoretically possible path traversal, see CWE-176: Improper Handling of Unicode Encoding for details. However, exploitation is not evaluated as real in the verinice usage scenario.
The update is accordingly recommended for all users who receive Microsoft Defender warnings during client installation under Windows.
As administrator of a verinice.PRO server, please also note the security notice at the end of these release notes!
New functions (verinice 1.26)
Risk Catalog ISO/IEC 27001:2022
With verinice 1.26 it is planned to publish the verinice risk catalog based on the new ISO/IEC 27001:2022.
The object Control will be extended by the new Attributes for this purpose:
- measure type is an attribute for the view of measures from the point of view of when and how a measure changes the risk in relation to the occurrence of an information security incident.
- Information Security Properties is an attribute for viewing measures from the standpoint of what protection goal the measure is intended to support. Cybersecurity Concepts looks at measures from the perspective of how measures map to the cybersecurity framework described in ISO/IEC TS 27110. Cybersecurity Framework.
- Operational Capabilities considers measures from the perspective of their operational information security capabilities and supports a practical user view of the measures.
- Security Domains are an attribute that allows measures to be viewed from the perspective of four information security domains.
Risk reports can be more easily customized by changing the risk parameters in the report templates to meet customer-specific requirements.
Bug fixes and detail improvements (verinice 1.26.1)
- Correction of the package signing to SHA-256.
- Improvement of Unicode encoding handling.
Bug fixes and detail improvements (verinice 1.26)
IT Baseline Protection
- The icon decorator for risk analysis in the modernized IT Baseline Protection are displayed independently of the authorization (action ID).
- Risk configuration* is displayed.
- The incorrect CSV import of business processes in modernized IT Baseline Protection has been fixed.
- Filtering takes into account objects that have multiple change types.
Business Continuity Management
- English translation was completed and some spelling errors were fixed.
Report templates
- In report A.1 Structural Analysis with Dependencies all linked objects are now displayed.
- In the report A.5 Risk Analysis all information about the information network is listed correctly.
- In the ISM report templates Risk Analysis and Risk Treatment, missing translations have been added.
vDesigner
- Fixed a bug that overwrote column names in report queries (encoding of the CSV-export can be specified in the settings).
General (Product Maintenance)
- Update of the RCP development framework to version 2022-09 (4.25).
- Update of the Java Development Kit in the client to JDK on 11.0.18+10.
- Group objects are correctly included in the search index.
- Translation of some properties in SNCA.xml added.
Security notes
New actions
none
Changed property files
- veriniceserver/WEB-INF/SNCA.xml veriniceserver/WEB-INF/snca-messages_??.properties
Database changes
none