Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryStandardsCompliance

BSI IT-Grundschutz

IT-Grundschutz is the BSI method for building an ISMS: BSI Standards 200-1 to 200-4 plus a Compendium of building blocks. How it works and when to use it.

Updated This page as Markdown

In short

IT-Grundschutz is the information security methodology of the German Federal Office for Information Security (BSI). Instead of deriving every control from your own risk analysis, you model your environment with building blocks from the IT-Grundschutz Compendium, each carrying basic, standard and elevated requirements. The BSI Standards 200-1 to 200-4 define the ISMS, the method, risk analysis and business continuity. It leads to an ISO 27001 certificate on the basis of IT-Grundschutz, issued by the BSI.

What is IT-Grundschutz?

IT-Grundschutz is the information security methodology published by the BSI, the German Federal Office for Information Security. Its core idea is reuse: the BSI has already analysed the typical threats to typical components and written down the requirements that address them. You model your environment with those building blocks instead of deriving each control from scratch, and you do your own risk analysis only where protection needs are high or where no suitable block exists.

The method has three approaches, defined in BSI Standard 200-2: basic protection (Basis-Absicherung) as a fast entry, core protection (Kern-Absicherung) for the crown jewels, and standard protection (Standard-Absicherung) as the full method that leads to certification. Protection needs are classified as normal, high or very high per asset.

Where is it defined?

Four BSI Standards define the method: 200-1 (requirements for an ISMS, compatible with ISO/IEC 27001), 200-2 (the IT-Grundschutz methodology), 200-3 (risk analysis) and 200-4 (business continuity management). The IT-Grundschutz Compendium holds the building blocks, organised in layers: ISMS, ORP (organisation and personnel), CON (concepts), OPS (operations), DER (detection and reaction), APP (applications), SYS (IT systems), IND (industrial IT), NET (networks) and INF (infrastructure). Every block lists basic requirements (must), standard requirements (should) and requirements for elevated protection needs, plus the elementary threats it addresses.

Certification is “ISO 27001 on the basis of IT-Grundschutz”: the BSI issues the certificate after an audit by a BSI-certified auditor. All documents are free to download from the BSI, which makes the Compendium one of the most concrete public sources of requirements available in German.

What it means in practice

The Compendium is precise where ISO/IEC 27001 is abstract. Where the ISO standard asks for “management of technical vulnerabilities”, a Compendium block says which service to disable and how to configure the component. That precision helps implementers and gives testers a checklist: when we test an environment that is modelled with IT-Grundschutz, the requirements of the blocks for web applications, network components, Windows clients and servers are what we check against, and the elevated requirements for high protection needs usually include penetration tests.

Patterns we see in Grundschutz-driven organisations:

  • Modelling without reality check. The information domain is modelled from the asset inventory, but the inventory is incomplete. A scan finds systems that belong to no block.
  • Basic protection treated as finished. Basis-Absicherung is an entry point. It is not the level the certificate requires and not the level an attacker respects.
  • OT modelled as IT. The IND blocks exist for a reason: a PLC cannot be patched like a server, and the blocks say how to compensate. Plants often model control systems with SYS blocks and then fail to meet them.

Zyberum conducts gap analyses against the Compendium, tests the environments it models, and supports operators of critical infrastructure in meeting the BSI’s proof requirements. We are not a BSI-certified auditor and do not issue certificates.

Common misunderstandings

IT-Grundschutz is not only for public authorities, even if that is where it is mandatory; any organisation can use it, and KRITIS operators often do. It is also not “the German ISO 27001”: it is a method that fulfils ISO/IEC 27001 in a defined way and produces a certificate recognised mostly in Germany. Finally, the Compendium is a catalogue of requirements, not an assurance that implementing them makes a system secure; the BSI itself expects regular tests and a risk analysis for anything with high protection needs.

FAQ

Frequently asked questions

Is IT-Grundschutz the same as ISO/IEC 27001?

No, but it leads to the same certificate. IT-Grundschutz is a method and a catalogue that fulfil the requirements of ISO/IEC 27001 in a prescribed way. The certificate "ISO 27001 on the basis of IT-Grundschutz" is issued by the BSI after an audit by a BSI-certified auditor. A native ISO/IEC 27001 certificate from an accredited certification body is the other route.

Who uses IT-Grundschutz?

Mainly German public administration, where it is often mandatory, and organisations that work for it or supply critical infrastructure. Companies with international customers more often choose native ISO/IEC 27001 because their customers know it. Many mix both: ISO/IEC 27001 as the frame, the Compendium as a free and very concrete source of requirements.

Does IT-Grundschutz cover OT?

Yes. The IND layer of the Compendium contains building blocks for operational and control technology, general ICS components, PLCs, sensors and actuators, machines, safety instrumented systems and industrial remote maintenance. They are a good starting point for a plant operator; IEC 62443 is deeper and internationally recognised.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab