Fundamentals
BSI IT-Grundschutz: telling the method, the standards and the Compendium apart
The standards explain the approach; the Compendium provides requirements for typical target objects. Only the modelling connects the two.
8 minute read · Content as of 21.07.2026
IT-Grundschutz is a complete security process
BSI Standard 200-1 describes the general requirements for an ISMS. Standard 200-2 specifies how an information security process is built with IT-Grundschutz. Standard 200-3 adds the risk analysis, Standard 200-4 business continuity management.
The IT-Grundschutz Compendium contains modules (Bausteine) for typical processes, applications, systems, networks and infrastructures. These modules are not adopted wholesale but modelled against your own information domain.
The method reduces recurring analysis work
For typical target objects, the threat landscape and the requirements are already structured. The organisation still has to check whether the domain under consideration carries particular risks, operating conditions or increased protection needs.
- Define the information domain and the scope
- Record business processes, information, applications and technology
- Determine protection needs and account for dependencies
- Model the appropriate modules and check the requirements
- Treat additional risks and keep the process up to date
Do not start with all the modules
An effective start begins with the security process and a clearly defined information domain. The free starter check shows whether these foundations are already sound.
Sources used
- BSI Standard 200-1 · BSI · Version 1.0
- BSI Standard 200-2 · BSI · Version 1.0 · October 2017
- IT-Grundschutz Compendium · BSI · Edition 2022
- Grundschutz practice patterns · KaitoSec