Glossary · Information security
Protection Needs Assessment (Schutzbedarfsfeststellung)
The IT-Grundschutz step that determines how strongly an information domain and its target objects need confidentiality, integrity and availability to be protected.
A protection needs assessment evaluates the possible damage if the confidentiality, integrity or availability of information and target objects is impaired. In BSI IT-Grundschutz, the result is documented as normal, high or very high for each of the three protection objectives.
The assessment starts with business processes and information and is transferred to the applications, IT systems, rooms and networks that support them. Dependencies and cumulative effects must remain visible so that the highest relevant need is not diluted.