00:00:00:00 - 00:00:01:01 Hello, everyone. 00:00:01:01 - 00:00:04:23 OSCAL has begin work in German security standard. 00:00:05:00 - 00:00:07:09 the German variant of NIST: the BSI 00:00:10:05 - 00:00:12:16 The Federal Bureau of Information Security 00:00:12:16 - 00:00:18:18 has opted to adapt OSCAL as the basis for the upcoming new standard. 00:00:18:18 - 00:00:23:17 That will be mandatory for pretty much all major industries in Germany, 00:00:23:17 - 00:00:28:24 because we have that new critics law, the nice way in Europe and Germany 00:00:28:24 - 00:00:33:09 will implement partly using the baseline Security protection 00:00:33:11 - 00:00:36:15 that the BSI already published, in a new version. 00:00:36:15 - 00:00:37:20 And that new version 00:00:37:20 - 00:00:41:07 is actually already delivered since close to a year in OSCAL. 00:00:41:07 - 00:00:45:21 I'm here to show you a little bit of the insights that we had on that journey. 00:00:45:21 - 00:00:49:02 I've been following the journey for quite some time now. 00:00:49:02 - 00:00:50:13 So about me. 00:00:50:13 - 00:00:54:17 Why I'm giving the talk is I've been involved with the IT baseline protection 00:00:54:17 - 00:00:59:01 manual for over 20 years now, And I've authored modules. 00:00:59:01 - 00:01:01:04 I’ve taken part in many projects. 00:01:01:04 - 00:01:04:12 I'm a lead auditor against the standard, have issued 00:01:04:19 - 00:01:07:23 certificates, and actually revoked two certificates as well. 00:01:07:23 - 00:01:12:22 So that has been an interesting time And from the start of this project, 00:01:12:22 - 00:01:17:17 to get the baseline protection manual into OSCAL, I was involved. 00:01:17:17 - 00:01:21:02 when the BSI set a so-called phase 1 00:01:21:02 - 00:01:25:03 that was meant to harvest the knowledge of all the people 00:01:25:03 - 00:01:28:22 that are involved with the baseline manual in getting the new standard going. 00:01:28:22 - 00:01:32:16 And that was community driven approach, and I took part in that. 00:01:32:21 - 00:01:35:10 What is the history of the whole thing? Where are we coming from? 00:01:35:10 - 00:01:36:13 It's a really old standard. 00:01:36:13 - 00:01:39:00 It pre-dates pretty much all security standards 00:01:39:00 - 00:01:42:23 we have today, because it already started in ‘92 with IT 00:01:42:23 - 00:01:47:16 security handbook and that was a collection of things to do best practices 00:01:47:16 - 00:01:52:06 that was already quite good structured, but was lacking in many regards. 00:01:52:06 - 00:01:56:02 For example, it didn't have a standard, but it was supposed to be 00:01:56:02 - 00:01:59:21 the guiding light, for at least the federal offices of all 00:01:59:23 - 00:02:04:09 Germany it had quite an impact on all the federal offices, 00:02:04:09 - 00:02:07:17 and it was meant to a more of a standard. 00:02:07:17 - 00:02:10:21 So the BSI went ahead and actually published 00:02:10:21 - 00:02:14:23 the first security standard in 2005 to the BSI 100 series, 00:02:14:23 - 00:02:20:07 and that was when they had an ISO 2701 alignment as well. 00:02:20:07 - 00:02:25:10 from then on, the baseline protection manual in Germany is considered 00:02:25:10 - 00:02:29:20 not a replacement, a local implementation of the ISO 2701. 00:02:29:20 - 00:02:35:03 So the certificate being issued against baseline protection are ISO 2701 00:02:35:09 - 00:02:37:23 certificates with international adoption. 00:02:37:23 - 00:02:40:21 Because BSI itself is used as also a 00:02:40:21 - 00:02:44:13 certificates and they accredited certification body, 00:02:44:13 - 00:02:49:04 so the certificates have a valid globally, which is a nice thing to do. 00:02:49:06 - 00:02:54:14 We have something that is a little bit more complicated than the NIST because the 2005 00:02:54:14 - 00:02:58:09 version was already something like 1000 pages that a little bit more 00:02:58:10 - 00:03:02:07 than the ISO in its native form has to offer, and it goes way more 00:03:02:07 - 00:03:06:13 into details. Back then all the modules for example, Windows Server 00:03:06:13 - 00:03:11:00 or general servers or clients or clients, There was something like 50 00:03:11:00 - 00:03:15:05 to 60 different modules, not like ISO in a form 00:03:15:05 - 00:03:19:22 of general security controls that need to be adapted to the technology. 00:03:19:22 - 00:03:24:08 But the BSI already did the adaption, so they took the ISO controls 00:03:24:08 - 00:03:28:18 and thought about, what risks does for example server Windows running has. 00:03:28:18 - 00:03:33:08 Which risks do we need to cover with a control, which measure that implements that control? 00:03:33:08 - 00:03:35:04 And that's what they put on paper. 00:03:35:04 - 00:03:40:14 So it's way more than the ISO because it’s a hardening. It's not only the what. 00:03:40:14 - 00:03:43:05 But includes the why and the how as well. 00:03:43:05 - 00:03:45:14 So that was quite a lot of pages. 00:03:45:14 - 00:03:49:19 And in 2017 when it all got a little bit out of hand 00:03:49:19 - 00:03:52:24 with like 5000 pages of hardening guides to 00:03:53:02 - 00:03:56:02 about 110 different system types. 00:03:56:04 - 00:04:00:11 As I said, from databases to servers, clients, locations as well. 00:04:00:11 - 00:04:03:13 ISO is not so much about physical security. 00:04:03:13 - 00:04:04:23 There's different standards for that. 00:04:04:23 - 00:04:09:04 But BSI includes everything from personal like how you hire people, 00:04:09:05 - 00:04:10:15 how you do background checks, 00:04:10:15 - 00:04:14:04 what kind of background checks are needed for certain types government 00:04:14:04 - 00:04:18:07 jobs, or in highly risk environment like banks and whatever. 00:04:18:07 - 00:04:21:16 That is one part and the other part is physical security as well. 00:04:21:16 - 00:04:27:06 So I think it's the only 360 degrees holistic security standard currently have there 00:04:27:06 - 00:04:30:23 Because it covers everything from how you pay for your parchment 00:04:30:23 - 00:04:32:16 to how you patched your server. 00:04:32:16 - 00:04:35:02 So that isn't really a good guiding light 00:04:35:02 - 00:04:38:16 for the people who need to follow it because some people actually need to follow it 00:04:38:18 - 00:04:39:23 For the federal government, 00:04:39:23 - 00:04:43:10 it is the law, for the localized government in our federal state. 00:04:43:11 - 00:04:48:17 It is not. Most federal governments have opted in using this guideline 00:04:48:17 - 00:04:50:03 from the federal government as well. 00:04:50:03 - 00:04:53:21 So it’s pretty much the law for everything bureaucracy. 00:04:53:21 - 00:04:57:22 And a lot of companies are forced to follow the standard. 00:04:57:22 - 00:04:58:12 For example, 00:04:58:12 - 00:05:03:09 if you do a public private partnership, we had one really large project in 2002. 00:05:03:10 - 00:05:05:06 That was my start by BSI Grundschutz 00:05:05:06 - 00:05:08:04 That is a traffic toll system called “Toll Collect”. 00:05:08:04 - 00:05:09:10 And they were required 00:05:09:10 - 00:05:13:16 to follow the recommendations by BSI as part of the contract. 00:05:13:16 - 00:05:16:06 So they needed to have a certification. 00:05:16:06 - 00:05:19:24 Otherwise they wouldn't be able to run the system for the state 00:05:19:24 - 00:05:23:01 and collect all the tolls from all the major roads in Germany. 00:05:23:01 - 00:05:24:11 So, that was a big deal for them. 00:05:24:11 - 00:05:29:18 And that was my personal start into the whole BSI and Grundschutz issue 00:05:29:21 - 00:05:34:19 In 2017 the protection manual was a little bit too big with 5000 pages. 00:05:34:19 - 00:05:37:24 So BSI decided that they need to get 00:05:37:24 - 00:05:40:24 that down to a more manageable level. 00:05:40:24 - 00:05:44:06 And before that it so much hardening guide. 00:05:44:06 - 00:05:46:06 And there many explanations 00:05:46:06 - 00:05:50:06 why you should do this and BSI wanted to remediate that. 00:05:50:06 - 00:05:55:20 And so they hired a few consultancies to do a total rewrite of the whole thing. 00:05:55:20 - 00:06:01:06 so starting 2015, we kind of rewrote the whole thing and wrote 1400 pages 00:06:01:06 - 00:06:02:10 of requirements. 00:06:02:10 - 00:06:07:01 it came from hardening guide explaining things to just requirements. 00:06:07:01 - 00:06:09:08 But still the requirements were in depth. 00:06:09:08 - 00:06:10:21 So we had requirements. 00:06:10:21 - 00:06:14:21 Still the modules and the modules went abou Windows, Linux. 00:06:14:21 - 00:06:18:12 we had modules for pretty much everything, and those modules consisted of 00:06:18:12 - 00:06:23:23 about ten pages each. Each of modules had something between 20 to 30 controls 00:06:23:23 - 00:06:27:06 this was the law until 2023 00:06:27:06 - 00:06:30:09 because that was the last edition of this compendium. 00:06:30:09 - 00:06:33:14 So since then the BSI is working on a new version, 00:06:33:14 - 00:06:36:16 and that new version is again a total overhaul. 00:06:36:16 - 00:06:41:06 Everything is changed nothing of the old texts are be remaining, 00:06:41:06 - 00:06:43:23 and this is something that BSI is still working 00:06:43:23 - 00:06:49:16 They released their first catalog, September 2025 and we can expect to be able 00:06:49:16 - 00:06:54:11 to certify against that early next year, so that much for the history of the whole thing 00:06:54:11 - 00:06:58:08 The current version you will find in the links that are provided in the slides. 00:06:58:10 - 00:07:01:12 There's everything the BSI is currently telling the people 00:07:01:16 - 00:07:05:02 The one thing that is currently missing is how to do it. 00:07:05:02 - 00:07:09:18 Like, there is no BSI 302. That is currently work in progress 00:07:09:18 - 00:07:13:17 But we are promised that we will be able to certify start of come next year. 00:07:13:17 - 00:07:15:00 So that's going to be interesting. 00:07:15:15 - 00:07:19:07 So the old version, we had planes where the modules 00:07:19:07 - 00:07:22:24 are sorted into like management system or IT systems networks. 00:07:22:24 - 00:07:25:11 And we had those many pages. 00:07:25:11 - 00:07:28:06 And of course we had the modal verbs As I said, it's 00:07:28:06 - 00:07:31:06 ISO 2701 in a local fashion, 00:07:31:07 - 00:07:34:18 more in-depth fashion, but still we call local version 00:07:34:18 - 00:07:36:11 and not a completely different thing. 00:07:36:11 - 00:07:39:05 So what is the BSI set out to do? 00:07:39:05 - 00:07:42:05 They came from pages then came a time 00:07:42:05 - 00:07:45:20 when got the data on HTML pages by BSI. 00:07:45:20 - 00:07:49:12 That was really nice to parse, because the HTML was always following 00:07:49:13 - 00:07:53:09 the same not only style guide, but the same text at the same places. 00:07:53:09 - 00:07:56:10 But then came the PDFs, and the PDF are really hard 00:07:56:10 - 00:08:00:20 to parse using Perl before the advent AI, of course. So that wasn't fun. 00:08:00:20 - 00:08:04:02 And everybody was complaining about this whole thing 00:08:04:02 - 00:08:08:06 not being machine readable, not being the basis for an ISMS 00:08:08:08 - 00:08:09:10 then came OSCAL 00:08:09:10 - 00:08:11:14 there would have been an option to just 00:08:11:14 - 00:08:17:01 take the old content and convert that but the BSI opted to create a new thing 00:08:17:01 - 00:08:21:17 One of the reasons was it was considered creating an OSCAL version of 1400 00:08:21:17 - 00:08:26:04 pages of printed stuff would months and years and would be really expensive. 00:08:26:04 - 00:08:30:03 to prove them wrong, I wrote an AI app over the weekend did that job 00:08:30:03 - 00:08:31:22 And that worked out quite well. 00:08:31:22 - 00:08:32:24 I will show that in a minute. 00:08:32:24 - 00:08:36:09 So we have the old edition 23, the old companion. 00:08:36:09 - 00:08:37:09 We have that in OSCAL. 00:08:37:09 - 00:08:39:09 We can use it in all the OSCAL tooling. 00:08:39:09 - 00:08:41:05 It's standards compliant OSCAL. 00:08:41:05 - 00:08:43:24 It conforms to all the schemas and the meta schemas. 00:08:43:24 - 00:08:48:04 So that's fine there. But of course it's not the new stuff that the BSI is creating. 00:08:48:04 - 00:08:51:23 they opted to have more an integrated approach like 00:08:51:23 - 00:08:55:17 they're not sorting They opted to get rid of the modules. 00:08:55:17 - 00:09:00:00 and now they call target object categories, which is pretty much modules. 00:09:00:00 - 00:09:04:22 But they opted to get rid of the how to implement something as well, 00:09:05:00 - 00:09:07:18 because that not considered to be state of the art 00:09:07:18 - 00:09:10:21 and really hard to maintain for so many different systems. 00:09:10:21 - 00:09:16:10 So now we have a catalog of 1000 controls, and those thousand controls are not how but 00:09:16:10 - 00:09:17:03 what to do. 00:09:17:03 - 00:09:22:11 The if is still based on security so all the assets get the list of controls. 00:09:22:11 - 00:09:25:17 And the list of controls is done by BSI and published. 00:09:25:17 - 00:09:27:08 So yeah old one 00:09:27:08 - 00:09:32:08 we had a sentence and that sentence had to be understood and implemented. 00:09:32:08 - 00:09:35:00 And we don't want that anymore. 00:09:35:00 - 00:09:36:17 but it's still a valid standard. 00:09:36:17 - 00:09:38:24 So what I said, going to show in a moment. 00:09:38:24 - 00:09:42:09 That the moment, what I did is I took all old PDFs, 00:09:42:09 - 00:09:48:00 I parsed them, used a lot of AI and got everything into JSON. 00:09:48:00 - 00:09:51:18 And you can download that JSON here on this URL. 00:09:51:18 - 00:09:55:05 I actually spent some tokens to translate it in like 14 languages, 00:09:55:05 - 00:10:00:10 So I can show that here, because I'm not planning to be just talking. 00:10:01:06 - 00:10:01:21 Where it is. 00:10:02:15 - 00:10:03:07 There we are. 00:10:03:07 - 00:10:06:11 So here you can get all the JSON. 00:10:06:11 - 00:10:08:04 You can get it translated. 00:10:08:04 - 00:10:13:07 You even get user defined modules Because the BSI has been a little bit slow 00:10:13:07 - 00:10:18:16 in issuing or releasing new modules for new technologies, something like 00:10:18:16 - 00:10:24:08 NoSQL databases or graph databases, things like that are totally missing. 00:10:24:09 - 00:10:26:14 CICD is missing as well. 00:10:26:14 - 00:10:32:14 All the processes that go with cloud, I added those things and included that 00:10:32:14 - 00:10:36:06 in the custom JSON that's a little bit bigger than the current. 00:10:36:06 - 00:10:40:10 If you really want to do a certification based on real standard, 00:10:40:10 - 00:10:41:20 you go for the current one. 00:10:41:20 - 00:10:44:23 And if you want to have all the other issues 00:10:44:23 - 00:10:49:10 covered, you can take the custom and say like, yeah, we did a risk analysis. 00:10:49:11 - 00:10:52:21 We came up with a list of measures that we need to do, this is it. 00:10:52:21 - 00:10:54:00 So that helps a lot. 00:10:54:00 - 00:10:56:11 All the code is obviously open source. 00:10:56:11 - 00:11:00:20 And if you want to do an old module, there's a skill for that as well. 00:11:00:20 - 00:11:05:08 You just take that SKILL.md and and put it into your favorite AI application. 00:11:05:08 - 00:11:09:20 And it will ask you a lot of questions about what security level 00:11:09:21 - 00:11:13:14 to achieve and things like then write your about time exactly 00:11:13:14 - 00:11:17:16 the way the BSI meant about time to So next slides. 00:11:18:01 - 00:11:20:19 So that is kind of helpful for the current situation. 00:11:20:19 - 00:11:24:01 But working with OSCAL I discovered a few things. 00:11:24:01 - 00:11:29:14 For example, it is great in a lot things, and I am happy for the BSI to have chosen 00:11:29:14 - 00:11:34:09 OSCAL as a foundation level of the new catalog, because I got to learn it 00:11:34:09 - 00:11:37:23 and I got to work with it quite a lot in the past one and a half years. 00:11:37:23 - 00:11:42:15 we could translate 99% of the BSI catalogs 00:11:42:15 - 00:11:46:11 and the new or the old compendiums and the new catalogs into OSCAL. 00:11:46:11 - 00:11:49:01 No problem. But I discovered a few problems as well. 00:11:49:01 - 00:11:51:22 For example, modality has no native field. 00:11:51:22 - 00:11:55:00 In BSI, we always have modality about controls 00:11:55:00 - 00:11:58:14 that needed to be put into the catalogs, into the profiles. 00:11:58:14 - 00:12:03:14 So we need to use props for that and role semantics were a little bit weaker 00:12:03:14 - 00:12:05:00 than BSI had that 00:12:05:00 - 00:12:08:02 The cross-reference that was just issued by NIST 00:12:08:05 - 00:12:09:12 actually a great help. 00:12:09:12 - 00:12:14:04 I was trying to do cross-referencing between standards, especially the new BSI 00:12:14:04 - 00:12:18:11 standards and the old BSI standard before the 1.2.1 release, 00:12:18:12 - 00:12:21:16 and that was really no fun but with that 00:12:21:16 - 00:12:24:16 new the eighth type file that is now possible. 00:12:24:16 - 00:12:26:18 in OSCAL, that is really nice. 00:12:26:18 - 00:12:28:04 it says like it's a forest. 00:12:28:04 - 00:12:31:12 But, if you can show it. It's sometimes a little bit complicated 00:12:31:12 - 00:12:36:13 to really show the crosslinks because not everything is a 1 to 1 relationship. 00:12:36:13 - 00:12:39:15 We have many end to end relationships and that is no fun. 00:12:39:15 - 00:12:43:02 But I don't think a problem with NIST or the OSCAL standard, 00:12:43:02 - 00:12:47:18 because that's just the real world of standards taking things a little bit different. 00:12:47:18 - 00:12:50:19 So the relationships are a little bit complicated. 00:12:50:19 - 00:12:56:03 Between the standards and 2016, I was tasked with doing the C5 addendum, 00:12:56:03 - 00:13:00:14 where the C5 is matched against all security standards on this planet, 00:13:00:14 - 00:13:02:21 or at least eight, nine, ten most important ones. 00:13:02:21 - 00:13:06:23 So if you find the old copy of the C5 with addendum matching 00:13:06:23 - 00:13:10:18 all the criteria of C5 to all the other standards, that was me. 00:13:10:18 - 00:13:12:02 And it was really tedious. 00:13:12:02 - 00:13:15:19 So I'm happy that NIST now has this format standardized. 00:13:15:19 - 00:13:20:03 So we can just add the connection between the one control to the other. 00:13:20:03 - 00:13:24:08 Something where we had problems with Germany, but that more of a user problem 00:13:24:08 - 00:13:26:21 Than the standards problem is moving branches like 00:13:26:21 - 00:13:30:10 BSI currently has not a real namespace going. 00:13:30:11 - 00:13:35:06 They use git as their name spacing and they are linking to main 00:13:35:06 - 00:13:39:16 and not to a tech branch or release or a certain commit. 00:13:39:16 - 00:13:42:00 So that is not really helping. 00:13:42:00 - 00:13:46:05 But they've actually changing that and new versions of JSON that are coming out 00:13:46:05 - 00:13:50:03 from the BSI and being published actually do use pinned commits. 00:13:50:03 - 00:13:54:05 So you have solved one major problem with working with a standard 00:13:54:05 - 00:13:55:24 that is published on GitHub. 00:13:55:24 - 00:14:00:14 That is which version of the standard you would like to certify against or prepare for 00:14:00:14 - 00:14:02:04 Is it commit A, commit B, 00:14:02:04 - 00:14:04:14 commit C, because there's currently no releases, 00:14:04:14 - 00:14:06:11 One thing that I discovered 00:14:06:14 - 00:14:10:07 that brings a lot of flexibility to OSCAL is the props, 00:14:10:07 - 00:14:14:16 because all the things I just said that was missing in OSCAL like modality 00:14:14:16 - 00:14:18:08 and many other values, they can be implemented as props 00:14:18:08 - 00:14:22:02 because props can go to each and any place in the JSON. 00:14:22:02 - 00:14:23:05 That is really helpful. 00:14:23:05 - 00:14:25:16 I implemented maturity levels using that. 00:14:25:16 - 00:14:29:20 I implemented list of a target where the control applies to 00:14:29:20 - 00:14:33:15 like if it's good for confidentiality or if it's good for integrity. 00:14:33:15 - 00:14:37:02 And I implemented that as props as well and a few other things 00:14:37:02 - 00:14:39:05 But of course then I had a tooling 00:14:39:07 - 00:14:43:16 that was knowing about all those props and that was using them to great effect. 00:14:43:16 - 00:14:46:16 But, no other tools on the planet could actually read my data 00:14:46:16 - 00:14:50:07 So this is when I started to have a look around and see that 00:14:50:07 - 00:14:54:20 quite a few organizations are currently implementing OSCAL, and using that file 00:14:54:20 - 00:14:58:23 format for their published standards, the props totally help in adapting 00:14:58:23 - 00:15:04:03 OSCAL to all their local histories, to their wordings, to how they do an ISMS, 00:15:04:03 - 00:15:07:19 How they do security controls, how they do hardening guides, whatever. 00:15:07:19 - 00:15:09:09 But it's a big risk as well. 00:15:09:09 - 00:15:13:10 Tools that are supposed to be OSCAL compliant will work with one 00:15:13:10 - 00:15:15:23 set of props from Germany, but they will not maybe 00:15:15:23 - 00:15:19:01 work with the props from Australia or Singapore or whatever. 00:15:19:01 - 00:15:24:18 So that is an issue for the future, I put a change request for that which is this one 00:15:24:18 - 00:15:28:24 I think it would be a good idea to define the props that are used 00:15:28:24 - 00:15:33:09 by this catalog or by this profile, So the catalog says, all controls 00:15:33:09 - 00:15:38:16 that I'll be inheriting from profiles, or I'll be defining myself in the catalog, 00:15:38:20 - 00:15:43:06 will use just 8 or 9 types props and the allowed values 00:15:43:06 - 00:15:48:00 for those props are listed because then people wouldn't be able to make mistakes. 00:15:48:00 - 00:15:50:17 For example, I can show one mistake here. 00:15:50:24 - 00:15:53:04 Just a second here the explorer. 00:15:53:04 - 00:15:58:12 If you look one of my applications, if you look for example, we have here a prop. 00:15:59:14 - 00:16:00:15 Here are my props 00:16:00:15 - 00:16:04:05 This just one of the controls in the new baseline catalog. 00:16:04:09 - 00:16:05:20 And it has all the stuff. 00:16:05:20 - 00:16:09:07 But then it stuff that OSCAL does not offer like security level, 00:16:09:07 - 00:16:12:17 an effort level, confidentially, integrity, availability. 00:16:12:19 - 00:16:16:12 Like a month ago, BSI started using those props 00:16:17:03 - 00:16:21:22 But then, if you had a defined set of and we would define in the catalog 00:16:22:00 - 00:16:25:23 which values such a prop may have, things like that could not happen 00:16:25:23 - 00:16:31:21 because it's actually not allowed in OSCAL to have comma separated values in a field. 00:16:31:21 - 00:16:36:05 This should be two props of name threats in the same or different namespace. 00:16:36:06 - 00:16:36:24 Same here like. 00:16:38:03 - 00:16:39:22 The tags are double as well. 00:16:40:23 - 00:16:46:20 So as you can see, if you look for props, I calculated it for one of my projects. 00:16:46:21 - 00:16:51:04 And BSI has something about 1000 controls in the catalog, 00:16:51:04 - 00:16:55:09 and there are 13,000 props, at median we have 13 props per control. 00:16:55:09 - 00:17:00:19 then the interoperability issue becomes a real issue, 50% of the data 00:17:00:19 - 00:17:04:00 that took from the old PDFs and put them into 00:17:04:00 - 00:17:07:14 OSCAL went into props. It works because the standard is flexible that way. 00:17:07:14 - 00:17:08:11 So that's great. 00:17:08:11 - 00:17:13:05 But a tool working for BSI controls will not work for other controls. 00:17:13:05 - 00:17:15:13 So that is interoperability issue. 00:17:15:13 - 00:17:19:18 But that's the tooling issue that people who want to sell on the German 00:17:19:18 - 00:17:23:04 market will need to do that and it kind of prevents 00:17:23:04 - 00:17:26:24 the possibility to have one big standard tool globally that reads all of them. 00:17:26:24 - 00:17:30:09 But then if you want to do a global product that caters to all the markets 00:17:30:09 - 00:17:34:04 you always have to adopt all the standards from those markets. 00:17:34:04 - 00:17:38:04 And pretty much every market has their own standards and OSCAL makes it easier 00:17:38:04 - 00:17:41:11 to adapt the tool to the standards, because I just have check 00:17:41:11 - 00:17:45:15 on a certain set of props and 50% of the data is already 00:17:45:15 - 00:17:49:05 in a conformant way, and just 50% I have to get from the props. 00:17:49:05 - 00:17:53:17 at way less effort in localizing a tool to a certain jurisdiction. 00:17:53:23 - 00:17:56:21 I actually cannot think of how to do this different. 00:17:56:21 - 00:17:59:21 yeah, happy with what OSCAL is delivering here 00:18:00:00 - 00:18:01:21 I think we made good use of it 00:18:02:17 - 00:18:03:09 Wrong window 00:18:03:18 - 00:18:05:24 Something funny here is 00:18:05:24 - 00:18:10:12 OSCAL defines for implementation states everything that is good. 00:18:10:12 - 00:18:14:16 I know OSCAL has a long history of not defining not implemented 00:18:14:16 - 00:18:18:14 something I would like to have because there's a between haven't looked at it 00:18:18:14 - 00:18:20:09 And no, it's not implemented. 00:18:20:09 - 00:18:21:14 That’s two different states. 00:18:21:14 - 00:18:25:08 And that would be really nice to be able to put them in JSON 00:18:25:10 - 00:18:26:21 XML, whatever file format. 00:18:26:21 - 00:18:31:12 But BSI went a little bit ahead and they reduced the number of allowed 00:18:31:12 - 00:18:35:09 implementation states to not implemented, which is not existing. 00:18:35:09 - 00:18:37:24 That was when I discovered that and implemented. 00:18:37:24 - 00:18:41:07 So this is some quirks from the German market. 00:18:41:07 - 00:18:45:17 Something I had to develop in the meantime was, for me, something like tooling. 00:18:45:17 - 00:18:47:10 I can show that here. 00:18:47:10 - 00:18:50:00 That is when you, 00:18:50:13 - 00:18:56:03 I created something like OSCAL Pruner and that is really thing to use 00:18:56:03 - 00:18:59:20 because when you work so large catalogs and you have. 00:18:59:23 - 00:19:01:05 no it takes a little a second. 00:19:03:08 - 00:19:06:04 When you work with large catalogs and you are using AI 00:19:06:04 - 00:19:07:03 You have the problem 00:19:07:03 - 00:19:11:04 You cannot fit something like 1000 controls into the context window. 00:19:11:04 - 00:19:12:13 So you have to do a selection. 00:19:12:13 - 00:19:15:00 And this is German module-based thing. 00:19:15:00 - 00:19:17:16 You can I don't know why this is so slow now. 00:19:17:16 - 00:19:19:14 Yeah. Usually you can click something here. 00:19:19:14 - 00:19:24:10 And then it opens and selects and de-selects and then you can export that 00:19:24:10 - 00:19:27:02 Yeah something is using my CPU 00:19:27:02 - 00:19:29:16 And then you get a pruned version 00:19:29:16 - 00:19:34:06 that is just a subset of the whole catalog for example, because BSI in the old version, 00:19:34:06 - 00:19:37:08 it was called Boorstin, and now it's called Thiele Object Card. 00:19:37:10 - 00:19:41:20 Category target object categories. You just take all the controls 00:19:41:20 - 00:19:46:10 that are required for some example a host system, Windows Server 00:19:46:10 - 00:19:50:17 and this tool that I’ve just failed to show gives you a list of all the controls 00:19:50:17 - 00:19:51:18 that applies to that. 00:19:51:18 - 00:19:55:06 And that can be the context for an AI that for example, 00:19:55:07 - 00:19:57:05 has to write a hardening guide for that. 00:19:57:05 - 00:19:59:12 So it knows like, oh, this is all the controls. Okay. 00:19:59:12 - 00:20:03:07 Now I write a measure for the controls that I'm seeing here. 00:20:03:07 - 00:20:07:00 And they give you an industrial best practice on how to do things. 00:20:07:16 - 00:20:09:09 but going forward. 00:20:09:09 - 00:20:11:08 So yeah, that is a pruner. 00:20:11:08 - 00:20:15:08 And something I did as a side hobby not related to 00:20:15:08 - 00:20:18:22 NIST or OSCAL just mentioning it, I was thinking about OSCAL 00:20:18:22 - 00:20:23:18 and how it works and out came JASCON, which is kind of JSON-based 00:20:23:18 - 00:20:26:10 How to do compliance notation But 00:20:26:10 - 00:20:28:06 it's yeah, was a weekend project 00:20:28:06 - 00:20:30:04 Something else I white-coded is 00:20:30:04 - 00:20:34:19 complete toolchain from the blueprint generator, that’s something special in Germany. 00:20:34:19 - 00:20:38:22 We used to have something like [standard-name]. 00:20:38:24 - 00:20:43:01 It's a security standard adapted to a certain kind of industry. 00:20:43:01 - 00:20:46:07 So for example, energy has their own security 00:20:46:07 - 00:20:51:10 standard and hospitals and hospitality all of them getting their own security 00:20:51:10 - 00:20:55:10 standard based on the baseline but still adapted to their needs, 00:20:55:10 - 00:20:59:06 maybe adding controls and of course putting in advice on 00:20:59:06 - 00:21:04:23 how to implement those controls, maybe including a scoping for a hospital like most 00:21:04:24 - 00:21:08:23 hospitals have a pretty similar scoping, and lots of people working in hospitals 00:21:08:24 - 00:21:13:10 can save a lot of work if they just had a template about a hospital 00:21:13:10 - 00:21:17:02 with the standard stuff that you find in like 99% of our hospitals. 00:21:17:02 - 00:21:18:20 So that was a nice thing to have. 00:21:18:20 - 00:21:21:23 And this is going to go into blueprints now. 00:21:21:23 - 00:21:25:21 But the slide has a mistake here It's actually an SSP generator. 00:21:25:21 - 00:21:29:16 Sorry for that So the SSP generator takes in data 00:21:29:22 - 00:21:33:10 from you, from the customer, from the user. And. 00:21:34:13 - 00:21:38:04 For example we already have here one okay. 00:21:38:05 - 00:21:39:14 We can restore it from here. 00:21:39:14 - 00:21:43:06 And then you can select for example. 00:21:43:09 - 00:21:44:18 Oh the funny thing is here. 00:21:44:18 - 00:21:46:18 Yeah you give it a name and things like that. 00:21:46:18 - 00:21:52:00 the fun thing here you can just upload documents, for example, 500 page PDFs 00:21:52:00 - 00:21:55:20 that explains your whole network, your whole setup, all your assets, 00:21:55:21 - 00:21:59:16 all your processes, all your risks, all your custom controls, 00:21:59:16 - 00:22:03:19 all your custom types of locations you have. it will send it to an AI 00:22:03:20 - 00:22:09:01 that you can configure in the background and will return you an SSP based on that data 00:22:09:01 - 00:22:12:01 With all the objectives or the modules and everything, 00:22:12:01 - 00:22:16:11 And then in the SSP editor, you will be able to edit that. 00:22:16:11 - 00:22:18:08 For example, you have. 00:22:18:08 - 00:22:20:00 My computer a little bit slow now. 00:22:20:00 - 00:22:21:08 Okay. now down here. 00:22:21:08 - 00:22:24:09 So you have an editor for the SSP. 00:22:24:09 - 00:22:27:09 So you can do everything you should do, fill in 00:22:27:09 - 00:22:30:24 parameters, type in commentary, tell like who was it? 00:22:30:24 - 00:22:31:24 when did it happen. 00:22:32:18 - 00:22:35:21 yeah, I'm not following the BSI lead and I'm actually 00:22:35:21 - 00:22:39:20 taking all the allowed states of a control into account here. 00:22:39:20 - 00:22:43:16 And I'm ignoring BSI on this not edited version 00:22:44:02 - 00:22:47:19 so that’s the editor and I'm pretty much out of time in two minutes 00:22:47:19 - 00:22:52:21 So you get an assessment plan, an assessment results editor as well. 00:22:52:21 - 00:22:57:05 This takes a little bit because it's like 1000 controls. 00:22:57:08 - 00:23:02:03 And in total we now have here quite a lot of 00:23:02:03 - 00:23:05:17 think a total we have 605 controls not that much. 00:23:06:14 - 00:23:08:07 And it's getting slow. 00:23:08:07 - 00:23:10:00 usually that works much better. 00:23:10:00 - 00:23:12:14 But my computer’s currently out of Ram or something 00:23:13:01 - 00:23:15:08 I tested it with 9000 controls 00:23:15:08 - 00:23:18:08 and it worked when I zoom open at the same So. 00:23:19:05 - 00:23:20:16 Go for the PoAMs 00:23:20:16 - 00:23:22:12 the plans, maybe have to close that here 00:23:22:12 - 00:23:25:16 But that is all the stuff I white coded 00:23:25:16 - 00:23:28:24 It usually works way better than it was showing. 00:23:28:24 - 00:23:30:15 Right now it's open source. 00:23:30:15 - 00:23:33:09 You can download under this URL 00:23:34:12 - 00:23:36:15 A little bit more of tooling. 00:23:36:15 - 00:23:37:17 what we want to achieve. 00:23:37:17 - 00:23:41:13 Everybody wants to achieve that BSI Germany is no outlier there. 00:23:41:13 - 00:23:43:24 We want to have continuous compliance. 00:23:43:24 - 00:23:48:14 We want to go away from the annual audit where everybody is running around 00:23:48:14 - 00:23:53:02 and it's being stressed out for six weeks or two months to something like a dashboard 00:23:53:03 - 00:23:57:16 that shows how much compliance is actually currently in the organization, 00:23:57:16 - 00:24:01:07 like is all the policies in accordance to the top level security policies? 00:24:01:08 - 00:24:05:21 Are the systems like we do in the cloud or everywhere else where we measure 00:24:05:22 - 00:24:08:23 security on a daily, on an hourly or maybe even 00:24:08:23 - 00:24:12:03 driven basis and go away from the yearly audit 00:24:12:03 - 00:24:16:14 to into something that we have a look every day So I'm out of time. 00:24:16:14 - 00:24:20:08 And this quite fitting because it is pretty much the last slide. 00:24:20:08 - 00:24:25:12 I've been using AI to write all that stuff using fable to discuss with me 00:24:25:12 - 00:24:30:08 how to notation for compliance things. Of the AI is really helpful in that. 00:24:30:08 - 00:24:33:23 But the verdict, the scoping, the risk acceptance. 00:24:33:23 - 00:24:38:11 And in the end someone has to take responsibility for it so that stays the human job 00:24:38:11 - 00:24:42:21 But the human that can do way more work in shorter time 00:24:42:21 - 00:24:45:15 So yeah, you've seen the URL, if you want to give it a try, 00:24:45:15 - 00:24:47:03 it's all in German right now. Sorry. 00:24:47:03 - 00:24:50:11 Because BSI baseline protection is a totally German thing. 00:24:50:11 - 00:24:54:11 Our colleagues in Austria even they don't do baseline protection manual. 00:24:54:12 - 00:24:57:23 They have their own thing which is kind of a copy from like 20 years back. 00:24:58:01 - 00:24:59:23 they're doing something new right now as well. 00:24:59:23 - 00:25:03:22 But if you find a bug, I'll be always happy to have feedback. 00:25:03:24 - 00:25:06:03 Yeah, compliance is code, continuous audit 00:25:06:03 - 00:25:08:14 and that's pretty much a first for me. Thank you.