[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83361-en":3,"doc-seo-83361-105":29,"detail-sidebar-cat-0-en-105":82},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":11,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},83361,1099514068365,"Aurelia","https://ap-avatar.wpscdn.com/avatar/10000253d8d9f28188e?_k=1776742907772140068",8,"Research & Report","Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy IT Security Concepts","The NIS-2 Directive accelerates the shift from manual, document-based compliance to machine-readable, continuously auditable compliance evidence. OSCAL (adapted in Germany via BSI’s Grundschutz++) enables this target, yet companies still rely on legacy IT security concepts that may be outdated or error-prone. The paper addresses the missing verification layer for migrating legacy IT-SCs by extracting them into a deterministically comparable intermediate graph, comparing against an independently verified reference topology, and exporting schemavalid OSCAL artifacts.","Reverse Engineering Compliance: A Dual-Graph Verification Framework for Auditing Legacy IT  \nSecurity Concepts  \nLea Muth  \nDepartment of Mathematics and Computer Science Freie Universitt Berlin Berlin, Germany [Lea.Muth@fu-berlin.de](Lea.Muth@fu-berlin.de)*  \nMarian Margraf  \nDepartment of Mathematics and Computer Science Freie Universitt Berlin Berlin, Germany [Marian.Margraf@fu-berlin.de](Marian.Margraf@fu-berlin.de)  \n9 Jul 2026  \nAbstract—The NIS-2 Directive increases the need for continuous, auditable compliance evidence and motivates a shift from document-based compliance toward machine-readable compliance artifacts. The Open Security Controls Assessment Language (OSCAL) is a standard for this purpose, which the German Federal Office for Information Security (BSI) is adapting with Grundschutz++. However, companies are still managing extensive legacy IT security concepts (IT-SCs), and migrating them without verification could transfer outdated assets into the new format. While existing research primarily addresses the generation of new concepts, there is a lack of a verification framework that extracts legacy IT-SCs into an auditable intermediate representation, deterministically compares the extracted graph with an independently constructed reference state, and exports schemavalid OSCAL artifacts. This paper introduces the Automated Security Concept Structure Extraction and Reverse Topology-  \narXiv :2607 .08292v1  \ndifferent levels of reference-ontology exposure. The evaluation shows that ASSERT makes document-infrastructure inconsistencies measurable, but reveals a trade-off between discovering undocumented entities and enforcing a schema.  \nIndex Terms—IT-Grundschutz, Grundschutz++, Compliance as Code (CaC), Open Security Controls Assessment Language (OSCAL), Knowledge Graph Extraction, Continuous Compliance  \nI. INTRODUCTION  \nWith the German implementation of the European NIS- 2 Directive [1] effective since 6 December 2025, IT risk management is shifting from manual, document-based compliance toward automated, data-driven compliance (Compliance as Code (CaC)) . A key technical foundation for this shift is the Open Security Controls Assessment Language (OSCAL) [2],  \n© 2026 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.  \na machine-readable format developed by the National Institute of Standards and Technology (NIST) . Structured data formats are not mandated by NIS-2 directly, but provide the technical foundation for continuous, scalable, and auditable compliance automation. In Germany, the Federal Office for Information Security (BSI) operationalizes this direction through Grundschutz++, which adopts OSCAL as a data model and moves the previously document-based IT-Grundschutz standard toward data-driven, evidence-based compliance artifacts. Although OSCAL defines the target format, many companies remain bound to legacy IT Security Concepts (IT-SCs) that are outdated, contain copy-paste errors, omit newly added assets, and include expired security measures. An unverified translation of these IT-SCs into OSCAL would follow the “garbage in, garbage out” principle. During the multi-year transition between IT-Grundschutz and Grundschutz++ (beginning in January, 2026), German organizations must still account for legacy IT-SCs alongside emerging machine-readable artifacts. Previous approaches toward automated compliance auditing mostly use Natural Language Processing (NLP) methods and Large Language Models (LLMs) to generate artifacts or prioritize vulnerabilities. Their probabilistic nature conflicts with the reproducibility and deterministic evidence handling required in security audits wheneve","cbCaisZ2hhBdMWlz","https://ap.wps.com/l/cbCaisZ2hhBdMWlz","pdf",250207,2,1,"English","en",105,"# Introduction\n## Problem and Motivation\n## Proposed ASSERT Framework\n### Deterministic Graph Comparison\n### Traceability and Ontology-Based Extraction","[{\"question\":\"How does the evaluation test ASSERT’s detection capability?\",\"answer\":\"The evaluation injects node- and edge-level faults into the reference IT-SC. It also studies how varying exposure of reference-ontology information during extraction affects the trade-off between discovering undocumented entities and enforcing schema constraints.\"}]",1784186993,20,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":77,"head_meta":79,"extra_data":81,"updated_unix":27},"reverse-engineering-compliance-a-dual-graph-verification-framework-for-auditing-legacy-it-security-concepts","",{"@graph":35,"@context":76},[36,52,67],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,46,49],{"item":40,"name":41,"@type":42,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":20},"https://docshare.wps.com/document/","Document",{"item":47,"name":12,"@type":42,"position":48},"https://docshare.wps.com/document/research-report/",3,{"item":50,"name":13,"@type":42,"position":51},"https://docshare.wps.com/document/reverse-engineering-compliance-a-dual-graph-verification-framework-for-auditing-legacy-it-security-concepts/83361/",4,{"url":50,"name":13,"@type":53,"author":54,"headline":13,"publisher":56,"fileFormat":59,"inLanguage":23,"description":14,"dateModified":60,"datePublished":61,"encodingFormat":59,"isAccessibleForFree":62,"interactionStatistic":63},"DigitalDocument",{"name":9,"@type":55},"Person",{"url":40,"name":57,"@type":58},"DocShare","Organization","application/pdf","2026-07-23","2026-07-16",true,{"@type":64,"interactionType":65,"userInteractionCount":20},"InteractionCounter",{"@type":66},"ViewAction",{"@type":68,"mainEntity":69},"FAQPage",[70],{"name":71,"@type":72,"acceptedAnswer":73},"How does the evaluation test ASSERT’s detection capability?","Question",{"text":74,"@type":75},"The evaluation injects node- and edge-level faults into the reference IT-SC. It also studies how varying exposure of reference-ontology information during extraction affects the trade-off between discovering undocumented entities and enforcing schema constraints.","Answer","https://schema.org",{"og:url":50,"og:type":78,"og:title":13,"og:site_name":57,"og:description":14},"article",{"robots":80,"canonical":50},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":83},[84,88,92,96,101,106,111,114,118,121,125],{"id":21,"doc_module":4,"doc_module_name":45,"category_name":85,"show_sort_weight":86,"slug":87},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":45,"category_name":89,"show_sort_weight":90,"slug":91},"Literature",80,"literature",{"id":51,"doc_module":4,"doc_module_name":45,"category_name":93,"show_sort_weight":94,"slug":95},"Exam",70,"exam",{"id":97,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},5,"Comic",60,"comic",{"id":102,"doc_module":4,"doc_module_name":45,"category_name":103,"show_sort_weight":104,"slug":105},6,"Technology",50,"technology",{"id":107,"doc_module":4,"doc_module_name":45,"category_name":108,"show_sort_weight":109,"slug":110},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":112,"slug":113},30,"research-report",{"id":115,"doc_module":4,"doc_module_name":45,"category_name":116,"show_sort_weight":28,"slug":117},9,"Religion & Spirituality","religion-spirituality",{"id":28,"doc_module":4,"doc_module_name":45,"category_name":119,"show_sort_weight":28,"slug":120},"World Cup","world-cup",{"id":122,"doc_module":4,"doc_module_name":45,"category_name":123,"show_sort_weight":122,"slug":124},10,"Lifestyle","lifestyle",{"id":126,"doc_module":4,"doc_module_name":45,"category_name":127,"show_sort_weight":97,"slug":128},19,"General","general"]