How does the risk analysis according to ISO 27001 differ from that according to BSI IT-Grundschutz?

ISO 27001 allows a flexible, risk-based methodology, whereas BSI IT-Grundschutz is more standardized and catalog-based. Both approaches, however, share the same goal: to make risks transparent and manage them appropriately. Leno supports both methods as well as hybrid approaches.

Weitere hilfreiche Antworten

Is the Leno GRC platform customizable as a No-Code solution?

Yes, as a modern cloud platform, Leno allows for No-Code configuration.

Yes, as a modern cloud platform, Leno allows for No-Code configuration. The solution is highly scalable and can be flexibly adapted to your internal structures, processes, and permission sets without any programming effort.

How does Leno replace manual Excel sheets with automated GRC workflows?

Leno eliminates manual errors through high-level automation and integrated AI

Leno eliminates manual errors through high-level automation and integrated AI. Structured workflows and built-in regulatory expertise replace tedious email-based coordination and static lists with a modern, digital process.

Can Leno link existing Third-Party Risk (TPRM) processes with Contract Management (CLM)?

Yes, Leno eliminates fragmented data silos by seamlessly linking vendors directly to their corresponding contracts, risks, and mitigation measures.

Yes, Leno eliminates fragmented data silos by seamlessly linking vendors directly to their corresponding contracts, risks, and mitigation measures. This seamless integration prevents redundant data entry and ensures full transparency.

What makes Leno the leading GRC platform for TPRM, CLM & ISR?

Leno is a modular GRC platform designed to digitalize and automate Governance, Risk & Compliance.

Leno is a modular GRC platform designed to digitalize and automate Governance, Risk & Compliance. It serves as a central hub for Third-Party Risk Management (TPRM), Contract Lifecycle Management (CLM), Information Security (ISM), and BCM.

What is a risk analysis according to BSI IT-Grundschutz and ISO 27001?

Risk analysis according to BSI IT-Grundschutz and ISO 27001 is used to systematically identify, assess, and prioritize information security–related risks. It forms the basis for selecting appropriate security measures within the framework of an ISMS.

How fast can Leno be deployed using onboarding and templates?

Thanks to pre-defined GRC templates and expert onboarding support, you can achieve a rapid "Go-Live".

Thanks to pre-defined GRC templates and expert onboarding support, you can achieve a rapid "Go-Live". We guide you from initial data migration to full production to ensure a smooth transition.

How does the risk analysis according to ISO 27001 differ from that according to BSI IT-Grundschutz?

ISO 27001 allows a flexible, risk-based methodology, whereas BSI IT-Grundschutz is more standardized and catalog-based. Both approaches, however, share the same goal: to make risks transparent and manage them appropriately. Leno supports both methods as well as hybrid approaches.

Is the platform available in multiple languages for global teams?

Yes, Leno supports English and German as standard.

Yes, Leno supports English and German as standard. Additional languages for international GRC teams can be added upon request to support your global compliance operations.

How does Leno handle user management and data security?

Security is ensured through Single Sign-On (SSO) and role-based access control (RBAC).

Security is ensured through Single Sign-On (SSO) and role-based access control (RBAC). Leno provides hosting and support directly from Germany, adhering to the highest security standards and architectural requirements.

Which risks must be considered as part of the risk analysis?

Risks arising from threats and vulnerabilities relating to information objects, processes and applications are considered. These include technical, organizational and external risks.

How often must a risk analysis be updated?

A risk analysis must be reviewed regularly and updated at least once a year. In addition, event-driven updates are required, for example, in case of changes in the information network, new threats, or significant process adjustments.

Which modules does Leno offer for DORA, BCM, and Contract Management?

Leno TPRM (Third-Party Risk & Outsourcing), Leno CLM (Contract Management), and Leno ISM (Information Security & BCM).

Leno is modular and fully integrated. We offer specialized modules: Leno TPRM (Third-Party Risk & Outsourcing), Leno CLM (Contract Management), and Leno ISM (Information Security & BCM). All modules work together to form a holistic GRC ecosystem.

What is the difference between a protection requirement analysis and a risk analysis?

The protection requirement analysis determines how valuable or sensitive information, processes, or applications are. The risk analysis then assesses the risks to which these protection requirements are exposed and evaluates the potential impacts. Both analyses logically build upon each other.

What role does risk analysis play in audits and certifications?

Risk analysis is a key audit criterion in ISO 27001 certifications and internal audits. Auditors expect a transparent methodology, up-to-date assessments, and a clear derivation of actions.

Our products

Third-Party Risk Management according to DORA, EBA Guidelines & MaRisk

Our TPRM and outsourcing management software enables compliant, transparent, and efficient lifecycle management of outsourcing arrangements, ICT services, and onward outsourcing in accordance with DORA, EBA Guidelines, and MaRisk. AI-driven automation delivers excellent usability, high data quality, and complete audit readiness.

Main functions
Explore Leno TPRM

AI-based contract lifecycle management (CLM) Software – intelligent and centralized

Our AI-powered, user-friendly, and automated software für contract lifecycle management (CLM) provides a dynamic hierarchical representation of all contract documents, continuous compliance with regulatory requirements, and transparent search and filter functions, including approval workflows and deadline monitoring.

Main functions
Explore Leno CLM

A solution for integrated ISM and BCM in accordance with international standards

Map a complete information ecosystem and connect all assets in real time. Our information security and Business Continuity Management (BCM) software enables you to conduct protection needs analyses, business impact analyses, and risk assessments, forming a fully integrated information risk management and BCM system.

Main functions
Explore Leno ISR

Get to know Leno

Book a demo
Book a meeting today to discover Leno.