IT-Grundschutz by the German BSI is the methodology for systematically building information security: the BSI standards (200-1 to 200-4) describe approach and risk management, while the IT-Grundschutz compendium provides modules with concrete requirements for typical components — from servers via networks to processes.
Its charm lies in concreteness: instead of abstract goals, Grundschutz names actionable requirements per module. It underpins many public sector mandates and is certifiable via ISO 27001 based on IT-Grundschutz.
How IT-Grundschutz is structured
The methodology leads via structural analysis and protection needs assessment to modelling: the information domain is assembled from compendium modules whose requirements are then implemented and checked. Three protection variants scale the effort — basic for getting started, standard for normal protection needs, core for concentrating on especially critical assets.
Particularly relevant for network and operations are the NET modules (network architecture, segmentation, WLAN, routers and switches), OPS modules for IT operations, and ORP and ISMS modules for organisation and management — including the requirement to separate networks by protection needs.
Using Grundschutz practically
- As a requirements catalogue: concrete audit questions per component instead of paper goals.
- As a maturity gauge: basic, standard or core protection depending on risk.
- As a certification path: ISO 27001 based on IT-Grundschutz for public sector contexts.
- As an argumentation aid: BSI recommendations carry weight in audits and budget rounds.