Obligations instead of statute names
What is assessed is the individual obligation at clause level, not the statute as a whole. Every assessment hangs off a catalog control and can be cross-linked with measures and ISMS controls.
Which rules apply to us, and who takes care of which clause?
ISO 27001 and most management systems require a register of binding obligations. In practice this is often a spreadsheet of statute names that nobody touches again. The legal register goes one level deeper: it maintains not just the norm but the individual obligation at clause level, assesses its relevance to your organisation, assigns an owner and a review cycle, and links it through the OSCAL catalogs to the measures and controls that satisfy it. When the version of a norm changes, the register reports it on its own.
What is assessed is the individual obligation at clause level, not the statute as a whole. Every assessment hangs off a catalog control and can be cross-linked with measures and ISMS controls.
A compliance profile describes the organisation, and a rule-based applicability check derives from it which norms are relevant at all. Non-applicability is thereby documented too.
An internal source watcher monitors the references and raises an alert on legal changes. Review cycles remind you in time instead of surfacing during the audit.
Alongside federal and EU law, the 16 German state data protection acts are included and automatically narrowed via the state assignment.
A solid answer to the audit question about binding obligations, including the justification for why a norm does not apply.
Schedule a no-obligation demo – we will show you the module with your own use cases.