Skip to content

Fundamentals

BSI IT-Grundschutz: telling the method, the standards and the Compendium apart

The standards explain the approach; the Compendium provides requirements for typical target objects. Only the modelling connects the two.

Back to BSI IT-Grundschutz

8 minute read · Content as of 21.07.2026

IT-Grundschutz is a complete security process

BSI Standard 200-1 describes the general requirements for an ISMS. Standard 200-2 specifies how an information security process is built with IT-Grundschutz. Standard 200-3 adds the risk analysis, Standard 200-4 business continuity management.

The IT-Grundschutz Compendium contains modules (Bausteine) for typical processes, applications, systems, networks and infrastructures. These modules are not adopted wholesale but modelled against your own information domain.

The method reduces recurring analysis work

For typical target objects, the threat landscape and the requirements are already structured. The organisation still has to check whether the domain under consideration carries particular risks, operating conditions or increased protection needs.

  • Define the information domain and the scope
  • Record business processes, information, applications and technology
  • Determine protection needs and account for dependencies
  • Model the appropriate modules and check the requirements
  • Treat additional risks and keep the process up to date

Do not start with all the modules

An effective start begins with the security process and a clearly defined information domain. The free starter check shows whether these foundations are already sound.

Sources used

Back to BSI IT-Grundschutz