Glossary · simply explained

IT-Grundschutz (BSI)

IT-Grundschutz by the German BSI is the methodology for systematically building information security: the BSI standards (200-1 to 200-4) describe approach and risk management, while the IT-Grundschutz compendium provides modules with concrete requirements for typical components — from servers via networks to processes.

Its charm lies in concreteness: instead of abstract goals, Grundschutz names actionable requirements per module. It underpins many public sector mandates and is certifiable via ISO 27001 based on IT-Grundschutz.

How IT-Grundschutz is structured

The methodology leads via structural analysis and protection needs assessment to modelling: the information domain is assembled from compendium modules whose requirements are then implemented and checked. Three protection variants scale the effort — basic for getting started, standard for normal protection needs, core for concentrating on especially critical assets.

Particularly relevant for network and operations are the NET modules (network architecture, segmentation, WLAN, routers and switches), OPS modules for IT operations, and ORP and ISMS modules for organisation and management — including the requirement to separate networks by protection needs.

Using Grundschutz practically

  • As a requirements catalogue: concrete audit questions per component instead of paper goals.
  • As a maturity gauge: basic, standard or core protection depending on risk.
  • As a certification path: ISO 27001 based on IT-Grundschutz for public sector contexts.
  • As an argumentation aid: BSI recommendations carry weight in audits and budget rounds.

Frequently asked questions about IT-Grundschutz (BSI)

What is the difference between IT-Grundschutz and ISO 27001?

ISO 27001 defines management requirements and leaves the choice of measures open; IT-Grundschutz additionally provides concrete, vetted requirements per module. Both combine in the certificate ISO 27001 based on IT-Grundschutz — widespread especially in the public sector.

Who benefits from IT-Grundschutz?

For public authorities and their providers it is often mandatory; companies use it as a concrete measures catalogue — even without certification plans. Mid-sized companies in particular benefit from the ready-made requirement lists instead of doing groundwork themselves.

What do basic, standard and core protection mean?

Three entry paths: basic protection implements the most important requirements quickly, standard is the complete approach for normal protection needs, core concentrates first on the most critical assets. Effort thus adapts to maturity and risk.

What does IT-Grundschutz say about networks?

The NET modules require a documented network architecture, separation of networks by protection needs, controlled transitions, secure administration and logging, among other things. Segmentation and Zero Trust access pay directly into these requirements.

How current is the compendium?

The BSI maintains the compendium continuously and regularly publishes revised editions with new and updated modules — including cloud, containers and modern ways of working. The current edition counts for implementation.

From term to implementation: KAEMI supports you from the first assessment to the ongoing managed service.