Skip to content

Methodology

Basic, Standard or Core Protection: which approach fits?

The three paths pursue different goals. The right choice depends on reach, time pressure and the desired evidence level.

Back to BSI IT-Grundschutz

7 minute read · Content as of 21.07.2026

Basic Protection prioritises breadth

Basic Protection aims to establish a broad initial level of protection across the institution. It is suitable when a fundamental security level needs to be reached quickly and then deepened systematically.

Core Protection prioritises particularly important areas

Core Protection concentrates the complete security process on a particularly sensitive part of the organisation first. It can make sense when critical services must be protected quickly and defensibly.

Standard Protection targets the complete domain

Standard Protection carries out the IT-Grundschutz methodology comprehensively for the information domain under consideration. The choice should be decided by the institution's management and documented with objective, scope and the intended path of expansion.

  • Desired security and evidence level
  • Criticality of the services
  • Available resources and time
  • Existing documentation and tool support

Sources used

  • BSI Standard 200-2 · BSI · Version 1.0 · October 2017
  • Grundschutz practice patterns · KaitoSec

Back to BSI IT-Grundschutz