Framework National Cyber & Cloud Schemes
IT-Grundschutz
IT-Grundschutz is the German Federal Office for Information Security's (BSI) methodology and control catalog for building an information security management system.
It consists of the BSI Standards (200-1 on ISMS requirements, 200-2 on the IT-Grundschutz methodology with its basic, standard, and core protection approaches, 200-3 on risk analysis, and 200-4 on business continuity) and the IT-Grundschutz-Kompendium, a catalog of modules (Bausteine) covering processes, applications, systems, networks, and infrastructure, each with specific requirements.
The 2023 edition of the Kompendium, with 111 modules in ten layers, is the current certification basis while BSI develops its successor, Grundschutz++ (verify status on the BSI site).
IT-Grundschutz is compatible with ISO/IEC 27001 and the BSI issues an "ISO 27001 certificate on the basis of IT-Grundschutz", which is the standard expectation for German federal agencies and common in German critical infrastructure and public sector supply chains.
In writing, an organization following IT-Grundschutz needs the security policy and ISMS scope, a structure analysis of the information domain (assets, applications, systems, networks, rooms), protection requirement determinations, the modeling that assigns Kompendium modules to assets, the IT-Grundschutz check recording each requirement's implementation status, a risk analysis for assets with high protection needs, the implementation plan, and the usual management system records.
The BSI certificate requires an audit by a BSI-certified auditor and is valid for three years with annual surveillance.
help
Who has to comply
German federal agencies are required to follow it under the federal IT security guideline (UP Bund); voluntary elsewhere but widely required in German public sector procurement, by KRITIS operators as a recognized route under the BSI Act, and by German enterprises that prefer a BSI-branded certificate over a plain ISO/IEC 27001 certificate.
What the assessor asks to see
Security policy and ISMS scope; structure analysis and asset register; protection requirement determination; modeling of Kompendium modules to assets; IT-Grundschutz check results per requirement; risk analysis for high protection needs; implementation plan and status; documented procedures for modules in scope; awareness training records; incident and business continuity documentation (BSI 200-4); internal audit and management review; the auditor's report and BSI review correspondence.
Assessors
Who assesses IT-Grundschutz
Auditors certified by the BSI for ISO 27001 audits on the basis of IT-Grundschutz; the audit report is reviewed by the BSI, which issues the certificate. Plain ISO/IEC 27001 certification against IT-Grundschutz-aligned controls can also be obtained from accredited certification bodies, but only the BSI issues the IT-Grundschutz certificate.
Accredited by BSI (as certification body and auditor licensor) for the IT-Grundschutz certificate; DAkkS-accredited certification bodies for conventional ISO/IEC 27001 certificates.
Public register of assessors: https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Standards-und-Zertifizierung/Zertifizierung-und-Anerkennung/Zertifizierung-von-Managementsystemen/ISO-27001-Basis-IT-Grundschutz/ErteilteZertifikate/iso27001zertifikate_node.html
No firm has claimed a IT-Grundschutz assessor listing yet. Claim yours →
Consultants
Who helps with IT-Grundschutz
A large German consultancy market and dedicated ISMS tool vendors support IT-Grundschutz implementation; BSI also licenses IT-Grundschutz practitioners and consultants through training schemes. Engagements run one to two years for a first BSI certification of a substantial scope.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a IT-Grundschutz consultant listing yet. Claim yours →
Software
Tools for IT-Grundschutz
Tools that name this framework in their own material.
Related reading
- IT-Grundschutz: audits and ISMS certificationAudit body's account of the ISO 27001 on the basis of IT-Grundschutz certification route and what the auditor examines.TUViT
- Germany IT-Grundschutz workbookShows how the OPS.2.2 Cloud Usage module is applied to a cloud deployment, and who produced the underlying workbook.Microsoft
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for IT-Grundschutz
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with IT-Grundschutz
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.