Asset & risk management depth
HiScout GRC Suite
The risk analysis is certified-in-practice methodology, not a flat list: BSI-Standards 200-3 and 100-3 with measure recommendations via cross-reference tables, and Grundschutz and BCM risk results consolidated in one tool and coordinated through to IT implementation. But we found no public information on incident handling workflows, NIS2 24h/72h reporting clocks, or risk acceptance with named ownership, and the only evidenced carry-over of ratings is between Kompendium editions rather than protection needs propagating across asset relations.
verinice
This is a real risk backbone: an ISMS built on BSI IT-Grundschutz methodology with automatic protection-needs inheritance across asset relations, object types running from target objects through requirements and measures to threats and risks, and NIS2 incident handling wired to the statutory clocks — report after 24 hours, situation report after 72 hours, final report after one month. Risk management per NIS2 Article 21 is integrated into both the Grundschutz and ISO 27001 domains, and ISO 27005 sits in the covered standards. What I could not find is risk acceptance with a named owner — who accepted which residual risk stays unevidenced.