Skip to content

BSI IT-Grundschutz · Working level

From the information domain to an auditable security concept.

Free templates and clear working steps for structural analysis, protection needs assessment, modelling and the IT-Grundschutz-Check.

Articles
8
Check questions
20
Templates
6
Chapters
7

Source-based orientation

Articles

  1. 01FundamentalsBSI IT-Grundschutz: telling the method, the standards and the Compendium apartThe standards explain the approach; the Compendium provides requirements for typical target objects. Only the modelling connects the two.8 min
  2. 02MethodologyBasic, Standard or Core Protection: which approach fits?The three paths pursue different goals. The right choice depends on reach, time pressure and the desired evidence level.7 min
  3. 03Structural analysisStructural analysis: capturing the information domain without getting lost in the inventoryBusiness processes first, technology second. That keeps visible which information and systems actually matter for the service.9 min
  4. 04Protection needsProtection needs assessment: justify categories instead of documenting gut feelingProtection needs arise from potential damage to processes and information. Inheritance and cumulation then carry them over to the technology.10 min
  5. 05ModellingIT-Grundschutz modelling: mapping modules cleanly onto target objectsThe modelling decides which requirements apply to which target objects. Mistakes here multiply across the entire IT-Grundschutz-Check.8 min
  6. 06IT-Grundschutz-CheckCarrying out the IT-Grundschutz-Check: from interview answer to a defensible statusImplementation status, justification, evidence and the open measure belong together. Otherwise the check remains a self-assessment.8 min
  7. 07RiskRisk analysis under BSI Standard 200-3: when IT-Grundschutz is not enoughAdditional risks are analysed where high protection needs, atypical operating conditions or insufficiently addressed threats exist.10 min
  8. 08BCMBSI Standard 200-4: connecting BCM with information securityBIA, continuity strategies, emergency plans and exercises need shared dependencies with the information domain.9 min

How it connects

Module layers

ISMS
Security managementProcess modules
Overarching governance of the information security process.
ORP · CON · OPS
Organisation and conceptsProcess modules
Organisation, personnel, concepts and operational security processes.
APP
ApplicationsApplication layer
Modules for general and specific applications and services.
SYS · IND
Systems and industrySystem layer
Servers, clients, devices, virtualisation and industrial components.
NET
Networks and communicationNetwork layer
Network architecture, network components and communication services.
INF
InfrastructureInfrastructure layer
Buildings, rooms, cabling and technical infrastructure.
DER
Detection and responseResponse layer
Detection, incident handling, forensics, audits and emergency management.

From knowledge into operation

Do not lose the results in yet another file.

KaitoSec connects requirements, owners, risks, controls and evidence in one working model.

Independent working aid of KaitoSec GmbH. Not a BSI publication, not official information from a public authority, and no substitute for the BSI audit basis current at any given time.

Content as of: 21 July 2026