Here you will find answers to the most frequently asked questions about mjEdit - from the origin of the name to target groups and roles to document control, AI analysis and OSCAL formats.
General
What is the usage context of mjEdit?
mjEdit is a specialized desktop application for all people and organizations who work with Information Security Management Systems (ISMS) on a daily basis. The primary context of use is the creation, maintenance, testing and control of ISMS documentation based on the OSCAL standard (Open Security Controls Assessment Language).
Typical application contexts are:
- Consulting companies that set up and operate ISMS projects for customers
- Information security officers (ISB / CISO) who control and document their ISMS on a daily basis
- Internal and external auditors who check and document ISMS implementations
- IT departments, which, as system owners, document the technical security implementation
- Multi-GRC environments in which several frameworks (BSI Grundschutz, ISO 27001, NIS2, TISAX, C5) are operated in parallel
What does the name “mjEdit” mean?
mjEdit stands for modular JSON editor. The name describes the technical core of the application: a highly specialized editor for JSON data that can be modularly expanded using a plugin system.
In practice, however, mjEdit is much more than an editor. It is a flexible tool that uses JSON data to cover a wide range of tasks and requirements in different application contexts - from OSCAL documentation to compliance dashboards to AI-supported analysis via MCP protocol.
What is the story of mjEdit?
mjEdit emerged from the daily workload of ISMS consulting for customers. In practice, there was a lack of a suitable tool to set up and operate ISMS projects professionally - without having to constantly switch between Word, Excel, PDF viewers and various online tools.
The result is an integrated work environment that covers exactly the tasks that arise in daily ISMS work: JSON editing, Markdown documentation, PDF annotation, OSCAL validation and AI support - all in a single interface.
Target groups
Who is the primary audience of mjEdit with the OSCAL plugin?
mjEdit with the OSCAL plugin is aimed at everyone who works daily in the ISMS environment:
| role | Task focus |
|---|---|
| ISMS Creator / Consultant | Creates and maintains information security concepts for customers; works daily with OSCAL catalogs, profiles and SSPs |
| Information Security Officer (ISB) | Actively supports the progress and implementation of the ISMS; uses mjEdit for progress controlling via dashboard |
| Internal auditor / auditor | Documents and checks ISMS implementation; requires complete traceability and audit-proof document history |
| IT employee / system owner | Documents the technical implementation of security measures in mjEdit |
What added value does mjEdit have for the ISB?
The ISB benefits from mjEdit primarily through less search effort, more overview and audit-proof documentation:
- Pre-installed compliance catalogs: BSI IT-Grundschutz++ (2,128 controls), NIST SP 800-53 (468 controls), C5, BSI 200-x - no manual typing from PDF sources.
- OSCAL dashboard: Control implementation progress at a glance - filtered by system, framework or responsible person.
- POA&M tracking: Open measures with deadlines, status and risk assessment centrally managed.
- Mapping between frameworks: C5 ↔ ISO 27001, BSI ↔ NIS2 – gap analysis with a click instead of manual work.
- Audit preparation: Cross-reference report immediately shows which controls are implemented, pending or not applicable.
- No tool change: JSON data, Markdown documentation, PDF checking and browser - all in one interface.
How would an ISB work with mjEdit?
A typical working day for the ISB with mjEdit could look like this:
- Morning: Open dashboard - open controls, overdue measures (POA&M) and upcoming audit dates at a glance.
- Control maintenance: Assign a new system owner to the control
OPS.1.1.5.A3and set the implementation status to “in implementation”.3. Risk work: Create a newly identified threat in the Risk tab, assign measures to it and have the risk value calculated. - Reporting: Export a current status report for management as a PDF from the Markdown editor.
- Audit preparation: Have a cross-reference report generated - ready for the external auditor.
Through AI integration via MCP, the ISB can delegate routine tasks: “Create a status report on all open POA&M entries with a deadline before August 31, 2026” - the AI generates the document automatically.
How would a consultant work with mjEdit?
As an ISMS consultant, you often work for several customers at the same time with different frameworks. mjEdit supports this workflow by:
- Multi-tab interface: Parallel editing of customer documents in multiple tabs - SSP customer A, catalog customer B, PDF document customer C.
- OSCAL project structure: A separate OSCAL document chain for each customer: Catalog → Profile → SSP → AP → AR → POA&M.
- Template library: Once created, baseline profiles for ISO 27001 or BSI Grundschutz can be cloned and customized for new customers.
- AI-supported analysis: Customer documents can be automatically analyzed, gaps identified and suggested measures generated using the MCP protocol.
- PDF annotation: Annotate customer documents directly in mjEdit and reference the references as OSCAL evidence.
A typical consulting workflow: Customer conversation → note results as Markdown → AI creates OSCAL measures from them → SSP is updated directly → report as PDF for the customer.
User management & roles
How is user and rights management in mjEdit?
mjEdit does not have a role-based rights concept as it is a local application. This is not needed in this form either, as every user works on the local data on their PC or with files on a network drive. The access rights of the network drive then determine the visibility of all files. But it makes a lot of sense if you work in a team that manages all files via GIT with or without a central server. This makes teamwork possible, which is also audit-proof.
Basic principles:
- OSCAL and mjEdit can define and document ISMS roles in the metadata of every document.
- ISMS roles can be assigned to systems in the documents to document responsibilities and responsibilities.
- Changes are logged in an audit-proof manner - who changed what and when if you save with revision.
How can mjEdit map the ISMS role concept?
mjEdit maps the ISMS role concept directly as accounts in the OSCAL tree view in the node: Metadata. There are predefined roles that can be assigned in the OSCAL documents.
| role | Application example |
|---|---|
| Administrator | Full access to an IT system e.g. E.g. user management, configuration |
| ISB / CISO | ISMS operator, release, reporting |
| Consultant | ISK creation in assigned projects |
| System Owner | System Component Owner, Creating OSCAL Components Files |
| Internal Auditor | Planning assessments, reading all documents, creating assessment results |
| External auditor | Planning audits, reviewing and evaluating evidence |
Own roles can be added to OSCAL documents to fully reflect the organization’s specific role concept.
OSCAL & Compliance
Who already uses OSCAL in Germany?
OSCAL is increasingly being used in Germany by authorities, certification bodies and companies that require structured, machine-readable compliance documentation. Well-known actors in German-speaking countries:
- BSI (Federal Office for Information Security): The BSI is actively monitoring OSCAL and has already prepared parts of the IT-Grundschutz compendium as an OSCAL catalog. mjEdit contains the BSI IT-Grundschutz++ catalog as a pre-installed database.
- Regulated Industries: Companies in energy, finance, healthcare and critical infrastructure use OSCAL to document NIS2 and KRITIS or ISO 27001 requirements in a structured manner.
- NIST users: Organizations that work according to NIST SP 800-53 or CSF (e.g. US branches) are already using OSCAL productively.OSCAL is a growing standard - the number of users in Germany increases with every NIS2 or BSI Grundschutz++ implementation project.
Are ISO 27001, NIS2 and TISAX available as OSCAL format?
Yes - the three most frequently requested frameworks are available in mjEdit as OSCAL catalogs or can be used directly:
| Framework | Status in mjEdit |
|---|---|
| ISO/IEC 27001:2022 | OSCAL catalog available; Controls as control objects with statements (but is only available once proof of licensing is available, please contact us) |
| NIS2 (EU Directive) | IN PREPARATION |
| TISAX (VDA ISA) | IN PREPARATION |
| BSI IT-Grundschutz++ | Pre-installed, complete as OSCAL catalog |
| NIST SP 800-53 Rev. 5 | Pre-installed, complete as OSCAL catalog |
| C5 (BSI Cloud) | Pre-installed, complete as OSCAL catalog |
Cross-framework mapping analyses (e.g. ISO 27001 ↔ NIS2 ↔ BSI Grundschutz) are possible directly via the mapping tab.
Document history & control
How can I see who made which changes and when?
mjEdit maintains an audit-proof document history directly when saving an OSCAL document. This means that every change to an OSCAL document can be logged automatically.
The history contains:
- Who made the change (user + role)
- When was the change made (time stamp, ISO 8601)
- What was changed (field level diff - what value was changed from what to what)
- Why was the change made (optional mandatory comment for security-related changes)
The history can be viewed directly in the Revision node and can be exported in the Markdown report.
How is document control carried out in mjEdit? How can an auditor understand this?
The Document control in mjEdit follows the ISMS standard for controlled documents:
- Versioning: Each OSCAL document contains version number,
last-modifiedtimestamp and author in the metadata - OSCAL compliant after v1.2.2. - Status Workflow: Documents go through defined statuses: Draft → In Review → Released → Archived. State transitions are role-bound (e.g. only ISB can release).
- Approval Process: Approvals are logged with user, timestamp and digital comment.
- Archival: Older versions are automatically archived and remain permanently accessible.
For auditors, mjEdit offers a dedicated Audit export: A complete, signable report with document history, change log, status timeline and all approvals - as a PDF or structured OSCAL AR document. This allows the auditor to fully understand who implemented and approved which security measure and when.
AI & Analytics
As an ISMS consultant, how can I create an analysis of customer documents using mjEdit and AI?
mjEdit offers more than 100+ tools** via the MCP protocol with full AI integration that significantly accelerates the analysis of customer documents. The typical analysis workflow:
Step 1 – Read documents: Customer documents (PDF, Word export, existing OSCAL files) are loaded into mjEdit. PDFs can be annotated directly; Texts are added to the local knowledge base via AnythingLLM-RAG.
Step 2 – AI-Powered Analysis: Through a connected AI agent (AnythingLLM-RAG, Claude Desktop, Cursor, VS Code Copilot), you ask questions in natural language:
“Analyze the customer documents and create a gap analysis against ISO 27001:2022. List all controls for which there is no evidence of implementation yet.”
Step 3 – Automated evaluation via MCP:
The AI calls up the appropriate tools via MCP tools such as oscal_compliance_check and oscal_mapping_auto_suggest and creates structured results directly in mjEdit.
Step 4 – Create Report:
A Markdown report is automatically generated from the results, which is exported as a PDF for the customer. Every statement in the analysis has a evidence-source reference - comprehensible and quotable.
Data protection: All analyzes run locally (AnythingLLM local, MCP server local) - customer data does not leave the environment.