Skip to content

We answer fast and to the point.

OSCAL tool for your ISMS

Import OSCAL catalogs, keep them current and version them.

Complaica is an OSCAL tool for managing security requirements in the ISMS. Integrate catalogs from the BSI and NIST as well as OSCAL catalogs of your own. Complaica updates connected catalogs automatically and regularly from external sources such as GitLab. Changes are marked; existing evaluations and the audit trail are kept.

  • 01Take over OSCAL catalogs with their controls and requirements
  • 02See new, changed and removed requirements
  • 03Trace catalog versions and go back when needed
  • 04Keep evaluations across catalog versions
01 OSCAL catalogs
02 Import a catalog online
03 Changes in a catalog version
04 Applicable standards
05 Catalog with requirements
OSCAL 01

Import OSCAL catalogs and manage them in the ISMS

Complaica connects OSCAL catalog management with the evaluation of security requirements in the ISMS. Imported controls and requirements are available in structured form and can be worked on together with the requirements of other frameworks.

  • 01Import an OSCAL catalog — from a released online source or as a catalog of your own
  • 02Controls and requirements are ready for evaluation in the ISMS with their structure
  • 03Importing again updates the same catalog instead of creating a second one
  • 04Several catalogs work on one shared stock of processes, assets and risks
  • 05Import and export OSCAL catalogs
01 Import a catalog online
OSCAL 02

Use the BSI’s and NIST’s catalogs together

If you work to more than one framework, you do not maintain several systems in Complaica: the official catalogs stand side by side and are evaluated on the same objects.

  • The BSI’s Grundschutz++ user catalog

    The user catalog (Anwenderkatalog) of Grundschutz++ is imported as an OSCAL catalog from the BSI’s official source. How Complaica supports the methodology is shown on the IT-Grundschutz page.

  • NIST SP 800-53

    NIST’s control catalog is available in the OSCAL format and is taken over as an OSCAL catalog.

  • One stock for both

    Processes, assets and risks are recorded once and are available to both catalogs — and to further standards such as ISO 27001.

  • Use your OSCAL catalog in Complaica

    Would you like to bring in a further OSCAL catalog? In the demo we check the import together and show you how to manage its requirements in Complaica.

01 OSCAL catalogs
OSCAL 03

Update OSCAL catalogs automatically

Publishers add, correct and remove. Complaica updates connected catalogs automatically and regularly from the external source in which they are maintained — a GitLab repository, for example.

  1. 01

    Connect the source

    The catalog is connected to its external source, for example a GitLab repository.

  2. 02

    Take over the new catalog version

    Complaica reads the source automatically and regularly and keeps every new state as a version of the catalog.

  3. 03

    Review the changes

    New, changed and removed controls and requirements are marked. Your team reviews precisely what the update touches.

OSCAL 04

Versioning and audit trail: evaluations are kept

After an update your team sees which requirements have changed. Existing evaluations and the history are kept. That makes it possible to check precisely which evaluations need adjusting.

01 Changes in a catalog version
  • Every catalog version stays traceable

    An update does not overwrite the catalog; it creates a new version. Which state applied when can be traced at any time.

  • Going back to an earlier version

    If a version does not fit, you reset the catalog to an earlier one.

  • New, changed, removed

    Every control and every requirement that an update added, changed or removed is marked. Your team can review changes precisely and judge their effect on existing evaluations and linked objects.

  • Evaluations are kept

    Existing evaluations are kept. Where the content of a requirement has changed, its validity should be reviewed again.

  • An audit trail without gaps

    The audit trail of changes is not lost in an update. The history is there for the next audit as well.

OSCAL 05

Bring in OSCAL catalogs of your own

Group policies, supplier requirements or customer requirements are defined as a catalog of your own in the OSCAL format, loaded into Complaica and used in parallel with the official catalogs of the BSI and NIST.

  • 01Define catalogs of your own in the OSCAL format and load them into Complaica
  • 02Work with them in parallel with the official catalogs
  • 03All frameworks draw on one shared stock of processes, assets, risks and vulnerabilities.

In Complaica’s ISMS software, IT-Grundschutz, ISO 27001 and NIS2 work on the same stock.

Request demo & prices

… or simply ask via WhatsApp.

01 Applicable standards
OSCAL 06

What is OSCAL?

OSCAL stands for Open Security Controls Assessment Language. The language, developed by NIST, describes security requirements, their implementation and assessments in standardised, machine-readable data models. An OSCAL catalog contains structured security requirements, known as controls. Complaica uses such catalogs as the basis for managing and evaluating requirements in the ISMS.

OSCAL connects to national and international standards — ISO 27001, NIST SP 800-53, IT-Grundschutz++ and further frameworks. Instead of Word files, Excel sheets or PDFs, requirements are available as structured data; that lowers maintenance effort, error-proneness and version confusion.

From requirements to review: a simplified OSCAL context

  1. 01

    Catalogs

    Requirements

    Subject-matter experts work out the requirements and publish them as a catalog.

  2. 02

    Profiles

    Tailoring

    An OSCAL profile selects controls from one or more catalogs and adapts them to a particular context of use.

  3. 03

    Measures

    Implementation

    Information security officers and administrators implement the requirements in the organisation.

  4. 04

    Reviews

    Audit

    Internally by the security officer and administration, externally by auditors and certification bodies.

OSCAL 07

Frequently asked questions about the OSCAL tool Complaica

What does an OSCAL tool do?

An OSCAL tool processes security requirements or other compliance data in the OSCAL format. Which functions it offers depends on the tool. Complaica imports and exports OSCAL catalogs, updates connected catalogs regularly and makes the changes between their versions visible.

Which OSCAL catalogs can I use in Complaica?

The BSI’s Grundschutz++ user catalog, NIST SP 800-53 and catalogs of your own in the OSCAL format — group policies, supplier requirements or customer requirements, for example. Whether a further catalog fits is something we clarify with you in the demo.

How are OSCAL catalogs updated?

The catalog is connected to an external source, for example a GitLab repository. Complaica takes over new states automatically and regularly as a new catalog version and marks new, changed and removed controls and requirements.

What happens to existing evaluations in an update?

Existing evaluations are kept, and so is the audit trail of changes. Where the content of a requirement has changed, its validity should be reviewed again — the marks show which ones those are.

Can I go back to an earlier catalog version?

Yes. Every catalog version is kept. If an update does not fit, you reset the catalog to an earlier version.

Can I use OSCAL catalogs of my own?

Yes. You define the catalog in the OSCAL format, load it into Complaica and use it in parallel with the official catalogs of the BSI and NIST.

Do several catalogs use the same assets and risks?

Yes. All frameworks draw on one shared stock of processes, assets, risks and vulnerabilities. An asset or a risk is recorded once and is available to every catalog.

OSCAL 08

See OSCAL catalog management live

See how import, automatic updates and versioning work together. Using your catalog, we show you how changes become visible and existing evaluations are kept.

✓Price list on request — we send it over
✓An offer within 24 hours
✓Migration of your data free of charge
✓Integration of your applications free of charge — tell us which ones
Request price list