Catalogs per sector, cleanly prepared
B3S Hospital (269 requirements, MUST/SHOULD/MAY, 41 chapters) and statutory health/care insurance come as structured, OSCAL-native catalogs with cross-references to other standards.
Sector-specific CI requirements: assessed, measured, audit-ready
Critical-infrastructure operators must regularly demonstrate under § 39 BSIG (formerly § 8a) that their protection matches the state of the art, and the yardstick is the sector-specific security standard. The B3S module ships the catalogs, first of all B3S Hospital with 269 requirements in MUST, SHOULD and MAY plus the catalog for statutory health and care insurance. Per scope you maintain the critical service, CI classification, evidence cycle and the statement of applicability. An auto-check engine tests as-is data from the platform against the requirements, RUN maturity for ISMS, BCMS and attack detection is calculated continuously, and the § 39 report for the audit emerges from day-to-day operations.
B3S Hospital (269 requirements, MUST/SHOULD/MAY, 41 chapters) and statutory health/care insurance come as structured, OSCAL-native catalogs with cross-references to other standards.
The auto-check engine tests requirements against real data from the platform, from inventory to policies, and shows where the evidence already sits.
Maturity and implementation levels for ISMS, BCMS and attack detection are calculated continuously; the § 39 audit report emerges from operations instead of an audit sprint.
The §8a evidence turns from a triennial tour de force into a report on a continuously measured state.
Schedule a no-obligation demo – we will show you the module with your own use cases.