The illustrations were created in cooperation between humans and artificial intelligence. They show a future in which technology is omnipresent, but people remain at the center.
AI-generated illustration
IT-Grundschutz++ and OSCAL – Transition to a Compliance Pipeline
From the New BSI Framework to Practical Implementation in the Workplace
This course is part of the certified Master Class "Machine Learning Engineer". If you book the entire Master Class, you save over 15 percent compared to booking this individual module.
The traditional IT-Grundschutz methodology is reaching its limits in many organizations: Outdated modules and extensive documentation requirements tie up resources and hinder efficient implementation. With IT-Grundschutz++ and the state-of-the-art library, the Federal Office for Information Security (BSI) is breaking new ground: moving away from static rulebooks toward practice-oriented “practices” and machine-readable OSCAL formats.
This reorientation opens up great potential for the automation of information security management systems—but at the same time presents companies with new challenges. In this practice-oriented training , you training how to apply the new structures operationally, modernize security processes, and successfully manage the transition from manual audits to an automated compliance pipeline.
Contents
Methodology and Architecture – The Evolution of the BSI Catalog
Analysis of the state-of-the-art library and its structure.
Strategic Paradigm Shifts in Business Practice.
A shift away from static rule sets toward dynamic security models.
Structure, hierarchy, and dependencies of the new catalogs.
“Practices” compared to traditional measures and components.
The Paradigm Shift – From Legacy Audits to the OSCAL Framework
Analysis of traditional audit approaches and their limitations.
Classification of existing automation solutions.
Introduction to the OSCAL Data Model.
Structural guidelines, data quality, and requirements.
Market overview and current tool landscape.
Toolchain in Practice – End-to-End Compliance
Working with the BSI-AG 3 demo implementation.
Completion of a full audit cycle.
IT asset inventory and mapping.
Performing an automated baseline security check.
Development and implementation of a POA&M (Plan of Action and Milestones).
Data Formats, Integration, and Architecture
Analysis of OSCAL-JSON structures at the code level.
Integration into existing IT and GRC environments.
Use of APIs and interfaces.
Integration into CI/CD and automation processes.
Strategic Implementation and Outlook
Building a scalable compliance pipeline.
Preparing for new testing realities.
Development of a roadmap for company-wide implementation.
Key factors for successful automation.
Your benefit
You understand the fundamental changes brought about by IT-Grundschutz++ and the State-of-the-Art Library.
You will learn how to apply OSCAL and machine-readable security requirements in practice.
You can evaluate traditional audit approaches and systematically integrate them into automated processes.
You will gain concrete insights into toolchains and their use in the context of auditing and compliance.
You will develop a solid foundation for building an automated compliance architecture.
trainer
Christoph Puppe
Methods
Expert insights and structured analysis of the new BSI approaches
Hands-on demonstrations and exercises using the BSI toolchain
Hands-on exercises covering the entire audit process
Discussion of integration and architectural issues
The NTT Grundschutz++ tools are used: https://github.com/NTT-Data-Deutschland-SE/Grundschutz-Plus-Plus-Tools
The illustrations were created in cooperation between humans and artificial intelligence. They show a future in which technology is omnipresent, but people remain at the center.
AI-generated illustration
The following training is now in the shopping cart
Building Data Analytics Solutions Using Amazon Redshift
Adaptable IT professional and seasoned instructor, bringing clarity to complexity with a quarter-century of diverse technological expertise
An accomplished IT professional with over 25 years in the field, I combine a developer's deep appreciation for code with an astute systems analyst's perspective. My expertise spans cloud and on-premise environments, and I am a strong proponent of DevOps principles and Infrastructure as Code. In addition to these, my years of experience in software development have helped me tackle complex challenges through fast prototyping and adopting various software design paradigms, delivering tailored software solutions. As a certified instructor for Amazon and Red Hat, I leverage my broad skill set and rich experience to demystify complex topics for students, reflecting my adaptability and commitment to continuous learning. Comfortable in diverse teams and with my ability to adapt to a wide range of situations, I utilize my technical proficiency and effective communication skills to drive successful outcomes in any setting.
AI-generated illustration
The illustrations were created in cooperation between humans and artificial intelligence. They show a future in which technology is omnipresent, but people remain at the center.