Map of BSI IT-Grundschutz — German national InfoSec framework from BSI (Bundesamt für Sicherheit in der Informationstechnik). National alternative to ISO 27001. Common in DE public sector, KRITIS critical infrastructure, Mittelstand. Now harmonized with ISO 27001 — Grundschutz-based certification under ISO 27001 possible. Reference cluster for DE-specific InfoSec engagement work.
Anchors
Provenance
- BSI — Bundesamt für Sicherheit in der Informationstechnik. German federal cyber agency. Established 1991. bund.de/BSI.
- IT-Grundschutzhandbuch — first edition 1994. Methodology + control catalog.
- BSI Standards 200-1, 200-2, 200-3, 200-4 — current methodology series replacing earlier 100-x series.
- IT-Grundschutz Kompendium — current catalog of building blocks (Bausteine). Annual edition; current ~2024/2025.
- ISO 27001 mapping — Grundschutz harmonized with ISO 27001; ISO 27001 certification "auf Basis IT-Grundschutz" available.
What IT-Grundschutz is
A methodology + control catalog for InfoSec management. Three core concepts:
- Schutzbedarfsfeststellung (protection requirement assessment): classify info / systems by protection requirement (normal / hoch / sehr hoch).
- Modellierung (modeling): map building blocks (Bausteine) to systems based on protection requirements.
- Sicherheitscheck (security check): assess implementation of measures.
BSI Standards series
BSI Standard 200-1: ISMS — Information Security Management Systems
High-level ISMS requirements. ISO 27001-compatible. Foundation.
BSI Standard 200-2: IT-Grundschutz Methodology
The methodology in detail. Three approaches:
- Basis-Absicherung (basic protection): minimum baseline.
- Standard-Absicherung (standard protection): default, comprehensive.
- Kern-Absicherung (core protection): focus on critical assets first.
BSI Standard 200-3: Risk Analysis
Risk analysis approach for systems with protection requirement "hoch" or "sehr hoch" or other risk-elevated situations.
BSI Standard 200-4: Business Continuity Management
Recently published. BCM methodology. ISO 22301-aligned.
IT-Grundschutz Kompendium
Catalog of building blocks (Bausteine) grouped:
- ISMS: management-level Bausteine.
- ORP (Organisation und Personal): organization, personnel.
- CON (Konzepte und Vorgehensweisen): concepts.
- OPS (Betrieb): operations.
- DER (Detection und Reaktion): detection, response.
- APP (Anwendungen): applications.
- SYS (IT-Systeme): IT systems.
- IND (Industrielle IT): industrial IT.
- NET (Netze und Kommunikation): networks, communications.
- INF (Infrastruktur): infrastructure.
Each Baustein:
- Has identification number (e.g., SYS.1.5 Virtualisierung).
- Lists threat catalog references.
- Defines required and optional measures.
- Categorized by lifecycle (planning, procurement, implementation, operations, decommissioning).
Annual updates expand catalog.
Detail in IT-Grundschutz Methodology and Bausteine.
Certification path
Three certification paths:
- ISO 27001 auf Basis von IT-Grundschutz — ISO 27001 certification using Grundschutz as implementation methodology. Issued by BSI-licensed auditors.
- IT-Grundschutz Testat — lower-tier confirmation.
- ISO 27001 standard — international standard certification.
Detail in IT-Grundschutz Certification.
KRITIS regulation
For critical infrastructure operators (KRITIS):
- BSI-Kritisverordnung defines KRITIS sectors and thresholds.
- KRITIS operators must implement state-of-the-art InfoSec (§8a BSIG).
- IT-Grundschutz commonly used as evidence framework.
- KRITIS reporting obligations under §8b BSIG.
NIS2 + KRITIS landscape currently being harmonized via NIS2UmsuCG.
Why this matters for SRE work
- DE public sector engagements: IT-Grundschutz often required.
- KRITIS clients: Mittelstand industrial / critical-infrastructure customers use Grundschutz.
- DE Mittelstand: many use Grundschutz instead of ISO 27001.
- NIS2 transposition (NIS2UmsuCG): Grundschutz methodology integrates with NIS2 obligations.
Related clusters
See also
BSI IT-Grundschutz Cluster (pillars MOC) · position · anchors · IT-Grundschutz Methodology and Bausteine · IT-Grundschutz Certification · IT-Grundschutz Controversies · ISO 27001 Cluster