BSI IT-Grundschutz · Working level
From the information domain to an auditable security concept.
Free templates and clear working steps for structural analysis, protection needs assessment, modelling and the IT-Grundschutz-Check.
- Articles
- 8
- Check questions
- 20
- Templates
- 6
- Chapters
- 7
Start from the work product
Read no more than the next step needs.
01
Assess your starting point
20 evidence-backed questions from the security process through to maintenance. The evaluation stays local in your browser.
02
Structure the implementation
7 chapters connect decisions to concrete outcomes.
03
Start from a template
6 open working aids for workshops, registers and reviews.
Source-based orientation
Articles
- 01FundamentalsBSI IT-Grundschutz: telling the method, the standards and the Compendium apartThe standards explain the approach; the Compendium provides requirements for typical target objects. Only the modelling connects the two.8 min
- 02MethodologyBasic, Standard or Core Protection: which approach fits?The three paths pursue different goals. The right choice depends on reach, time pressure and the desired evidence level.7 min
- 03Structural analysisStructural analysis: capturing the information domain without getting lost in the inventoryBusiness processes first, technology second. That keeps visible which information and systems actually matter for the service.9 min
- 04Protection needsProtection needs assessment: justify categories instead of documenting gut feelingProtection needs arise from potential damage to processes and information. Inheritance and cumulation then carry them over to the technology.10 min
- 05ModellingIT-Grundschutz modelling: mapping modules cleanly onto target objectsThe modelling decides which requirements apply to which target objects. Mistakes here multiply across the entire IT-Grundschutz-Check.8 min
- 06IT-Grundschutz-CheckCarrying out the IT-Grundschutz-Check: from interview answer to a defensible statusImplementation status, justification, evidence and the open measure belong together. Otherwise the check remains a self-assessment.8 min
- 07RiskRisk analysis under BSI Standard 200-3: when IT-Grundschutz is not enoughAdditional risks are analysed where high protection needs, atypical operating conditions or insufficiently addressed threats exist.10 min
- 08BCMBSI Standard 200-4: connecting BCM with information securityBIA, continuity strategies, emergency plans and exercises need shared dependencies with the information domain.9 min
How it connects
Module layers
- ISMS
- Security managementProcess modules
- Overarching governance of the information security process.
- ORP · CON · OPS
- Organisation and conceptsProcess modules
- Organisation, personnel, concepts and operational security processes.
- APP
- ApplicationsApplication layer
- Modules for general and specific applications and services.
- SYS · IND
- Systems and industrySystem layer
- Servers, clients, devices, virtualisation and industrial components.
- NET
- Networks and communicationNetwork layer
- Network architecture, network components and communication services.
- INF
- InfrastructureInfrastructure layer
- Buildings, rooms, cabling and technical infrastructure.
- DER
- Detection and responseResponse layer
- Detection, incident handling, forensics, audits and emergency management.
From knowledge into operation
Do not lose the results in yet another file.
KaitoSec connects requirements, owners, risks, controls and evidence in one working model.
Independent working aid of KaitoSec GmbH. Not a BSI publication, not official information from a public authority, and no substitute for the BSI audit basis current at any given time.
Content as of: 21 July 2026