
Excel vs. OSCAL: How “Grundschutz++” Becomes a Manageable ISMS
Grundschutz++ is being published as an OSCAL data model. Why Excel falls short - and how a GRC tool can turn it into an audit-proof ISMS.
Topic
When & Where
Details
Format:
Management lecture
Language:
German
Session description
Speaker: Silke Menzel
“G++_Risk_Analysis_V2_final_secure.xlsx” - if that filename sounds familiar, then you know the problem. Grundschutz++ is just around the corner, and with it comes a radical change: The new BSI standard will no longer be published as a PDF compendium, but as an OSCAL data model. The machine-readable standard from the U.S. National Institute of Standards and Technology (NIST) is a graph consisting of practices, requirements, roles, and target object categories with fixed Control IDs. Anyone who wants to map this in Excel ends up flattening out precisely the relationships that later form the basis of the model.
Why does Excel fail so reliably here? The presentation gets to the bottom of four practical problems. First, the flood of versions: n versions are ...

