General session image of Knowledge Forum F

Excel vs. OSCAL: How “Grundschutz++” Becomes a Manageable ISMS

Grundschutz++ is being published as an OSCAL data model. Why Excel falls short - and how a GRC tool can turn it into an audit-proof ISMS.

Topic

Governance, Riskmanagement and Compliance

When & Where

calendar_month

Wed, 10/28/2026 12:00 PM - 12:15 PM

location_on

Forum F, Booth 9-638

Download session as iCaldownload_for_offline

Details

  • Format:

    Management lecture

  • Language:

    German

Session description

Speaker: Silke Menzel

“G++_Risk_Analysis_V2_final_secure.xlsx” - if that filename sounds familiar, then you know the problem. Grundschutz++ is just around the corner, and with it comes a radical change: The new BSI standard will no longer be published as a PDF compendium, but as an OSCAL data model. The machine-readable standard from the U.S. National Institute of Standards and Technology (NIST) is a graph consisting of practices, requirements, roles, and target object categories with fixed Control IDs. Anyone who wants to map this in Excel ends up flattening out precisely the relationships that later form the basis of the model.

Why does Excel fail so reliably here? The presentation gets to the bottom of four practical problems. First, the flood of versions: n versions are ...

Sponsored by