German-language gatekeeping
Methodology and most Kompendium content primarily German. Effects:
- International orgs face translation friction.
- Non-German practitioners struggle.
- Smaller export limit on Grundschutz adoption outside DE.
Bureaucratic implementation patterns
Public-sector lineage produces ceremonial implementation:
- Heavy documentation focus.
- Ritual compliance rather than substantive security.
- Variance between mature and ceremonial implementations.
Kompendium navigation cost
Catalog is large:
- Hundreds of Bausteine across sectors.
- Many cross-references.
- New users face steep learning curve.
Update cycle lag
Annual updates trail threat landscape:
- AI / generative AI coverage emerging but light.
- Cloud-native and container Bausteine maturing.
- Some legacy Bausteine reflect outdated patterns.
ISO 27001 vs IT-Grundschutz tension
Two paths exist; choice involves trade-offs:
- ISO 27001 international vs Grundschutz DE-specific.
- Procurement preferences vary.
- Some orgs maintain both, doubling overhead.
DE public-sector lock-in
Heavy public-sector dependency:
- Funding cycle dependencies.
- Resource constraints at BSI affect responsiveness.
- Mission scope expansion (KRITIS, NIS2) stretches capacity.
Counterpoint
- DE national authority weight.
- Rich threat catalog.
- Prescriptive Bausteine reduce implementation ambiguity.
- ISO 27001 harmonization preserves international optionality.
- KRITIS sector orientation valuable.