Asset & risk management depth
HiScout GRC Suite
The Grundschutz pages show a real, documented risk methodology — BSI-Standard 200-3 and 100-3 with measure suggestions drawn from the Kompendium cross-reference tables — and Grundschutz and BCM risk analyses converging in one tool down to IT implementation. But we found no public information on incident workflows, statutory reporting clocks, or risk acceptance with named ownership, and protection-needs inheritance across asset relations is never spelled out.
verinice
The BSI methodology is implemented as real objects — targets, requirements, measures, threats, risks — with automatic protection-needs inheritance and supporting structural analysis, and the NIS2 domain carries the statutory clocks (report after 24 hours, situation report after 72 hours, final report after one month). Risk management per NIS2 Article 21 is documented as integrated into both the Grundschutz and ISO 27001 domains. We found no public information on risk acceptance with named ownership or executive-level risk reporting.