Risk
Risk analysis under BSI Standard 200-3: when IT-Grundschutz is not enough
Additional risks are analysed where high protection needs, atypical operating conditions or insufficiently addressed threats exist.
10 minute read · Content as of 21.07.2026
What does BSI Standard 200-3 cover?
BSI Standard 200-3 describes risk analysis on the basis of IT-Grundschutz. It starts where standard protection under BSI Standard 200-2 is not enough and leads in six steps from selecting the target objects to feeding the results back into the security process. The 47 elementary threats in the IT-Grundschutz Compendium are the starting point of every threat overview.
- Preparation: determine the target objects that need a risk analysis
- Threat overview: check the elementary threats per target object and add specific threats
- Risk classification: rate frequency and impact and assign a risk category through the risk matrix
- Risk treatment: decide and justify avoidance, reduction, transfer or acceptance per risk
- Consolidation: add the supplementary safeguards to the security concept and check for contradictions
- Feedback: carry the results into the IT-Grundschutz-Check and the ongoing security process
The risk analysis complements the modelling
IT-Grundschutz methodically covers typical threats at normal protection needs. An additional risk analysis becomes necessary when those preconditions do not hold or particular risks are apparent.
The transition must be documented
Triggers, the target objects considered, additional threats and decisions should be clearly referenced. That keeps visible which IT-Grundschutz requirements are already effective and which supplementary measures are required.
- Target objects with high or very high protection needs
- Atypical or particularly exposed deployment scenarios
- Technologies that cannot be fully modelled
- Findings from incidents, audits or threat analyses
A lean risk sheet is enough to start
The free Markdown template brings together target object, threat, existing safeguards, assessment, supplementary measure and approval.
Sources used
- BSI Standard 200-2 · BSI · Version 1.0 · October 2017
- BSI Standard 200-3 · BSI · Version 1.0
- Grundschutz practice patterns · KaitoSec